Bug 1179532 (CVE-2020-27819) - VUL-1: CVE-2020-27819: libxls: NULL pointer dereference via crafted xls file
Summary: VUL-1: CVE-2020-27819: libxls: NULL pointer dereference via crafted xls file
Status: RESOLVED FIXED
Alias: CVE-2020-27819
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/272580/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-12-02 14:02 UTC by Robert Frohl
Modified: 2024-05-14 10:38 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2020-12-02 14:02:26 UTC
rh#1903296

An issue was discovered in libxls reading Excel files before 1.6.1. A NULL pointer dereference vulnerability exists when parsing xls cells in libxls/xls2csv.c:199. It could allow a remote attacker to cause a denial of service via crafted xls file.

Reference:
https://github.com/libxls/libxls/issues/84

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1903296
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-27819
Comment 1 Robert Frohl 2020-12-02 14:03:10 UTC
Already fixed in openSUSE:Factory, but still relevant for Leap 15.2
Comment 2 Robert Frohl 2020-12-02 14:15:46 UTC
should have been an openSUSE bug, sorry about the oversight. Let me know if this is causing access issues.
Comment 3 Jan Engelhardt 2020-12-02 18:18:34 UTC
dbed5f2 is not in any released version, so this still affects TW too.
Comment 4 Jan Engelhardt 2021-05-25 08:19:30 UTC
dbed5f2 is in libxls-1.6.2; TW is fine; more RQs have just been issued.
Comment 5 OBSbugzilla Bot 2021-05-25 08:50:03 UTC
This is an autogenerated message for OBS integration:
This bug (1179532) was mentioned in
https://build.opensuse.org/request/show/895301 Backports:SLE-15-SP3 / libxls
https://build.opensuse.org/request/show/895302 15.2 / libxls
Comment 6 Swamp Workflow Management 2021-05-30 16:17:53 UTC
openSUSE-SU-2021:0812-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1179532
CVE References: CVE-2020-27819
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    libxls-1.6.2-lp152.2.3.1
Comment 7 Swamp Workflow Management 2021-07-08 19:24:06 UTC
openSUSE-SU-2021:0992-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1179532
CVE References: CVE-2020-27819
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP3 (src):    libxls-1.6.2-bp153.2.3.1