An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability
| Software | From | Fixed in |
|---|---|---|
| libxls_project / libxls | 1.3.4 | 1.3.4.x |
| debian / debian_linux | 9.0 | 9.0.x |