An exploitable integer overflow vulnerability exists in the xls_preparseWorkSheet function of libxls 1.4 when handling a MULBLANK record. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
| Software | From | Fixed in |
|---|---|---|
| libxls_project / libxls | 1.4 | 1.4.x |