Impact
A flaw in the xls_dumpSummary() routine of libxls 1.6.3 allows an out‑of‑bounds read when file‑controlled OLE summary offsets are not properly verified. The vulnerability can expose sensitive data from memory or cause a crash, thereby impacting confidentiality and availability of the process that parses the affected Excel files.
Affected Systems
Any system using libxls 1.6.3 to read or process .xls files is at risk. No vendor maturity information is available, but the flaw affects the core library functions that handle summary metadata extraction.
Risk and Exploitability
The flaw permits an attacker to supply a maliciously crafted Excel file that will cause the library to read beyond the intended buffer. While no CVSS score is listed and the EPSS value is unavailable, the absence of validation makes exploitation straightforward for an attacker who can deliver a file to the application. The vulnerability is not currently listed in CISA KEV, but its potential for information leakage or denial of service warrants cautious remediation.
OpenCVE Enrichment