Impact
A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3. The flaw stems from insufficient validation of a file-controlled font index, allowing a crafted XLS file to corrupt memory and potentially execute arbitrary code or crash the application. This weakness is identified as CWE-122.
Affected Systems
The vulnerability affects the libxls library. Any application that includes libxls 1.6.3 for parsing Excel (.xls) files is potentially exposed.
Risk and Exploitability
The flaw is triggered by processing a malicious XLS file, so the attack vector is likely local through a supplied spreadsheet. An attacker who can supply a specifically crafted file to the vulnerable process can exploit the buffer overflow and free denial to achieve arbitrary code execution. The EPSS score is <1%, it is not listed in CISA KEV, and the CVSS score of 7.8 indicates high severity.
OpenCVE Enrichment