CVE-2017-2923

Source
https://cve.org/CVERecord?id=CVE-2017-2923
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-2923.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-2923
Downstream
Related
Published
2018-04-24T19:29:03.860Z
Modified
2026-02-10T15:34:00.621707Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An exploitable heap based buffer overflow vulnerability exists in the 'readbiffnext_record function' of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.

References

Affected packages

Git / github.com/gstreamer/gst-plugins-ugly

Affected ranges

Type
GIT
Repo
https://github.com/gstreamer/gst-plugins-ugly
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
Other
BEFORE_INDENT
BRANCH-ERROR-ROOT
BRANCH-EVENTS2-ROOT
BRANCH-GSTREAMER-0_8-ROOT
CAPS
CAPS-MERGE-3
CAPS-ROOT
CHANGELOG_START
GIT_CONVERSION
MOVE-TO-FDO
OSLOSUMMIT1-200303051
RELEASE-0_10_0
RELEASE-0_10_1
RELEASE-0_10_10
RELEASE-0_10_11
RELEASE-0_10_2
RELEASE-0_10_3
RELEASE-0_10_4
RELEASE-0_10_5
RELEASE-0_10_6
RELEASE-0_10_7
RELEASE-0_10_8
RELEASE-0_10_9
RELEASE-0_9_1
RELEASE-0_9_3
RELEASE-0_9_4
RELEASE-0_9_5
RELEASE-0_9_6
RELEASE-0_9_7
TYPEFIND-ROOT
start
RELEASE-0.*
RELEASE-0.10.12
RELEASE-0.10.13
RELEASE-0.10.14
RELEASE-0.10.15
RELEASE-0.10.16
RELEASE-0.10.17
RELEASE-0.10.18
RELEASE-0.11.1
RELEASE-0.11.2
RELEASE-0.11.90
RELEASE-0.11.91
RELEASE-0.11.92
RELEASE-0.11.93
RELEASE-0.11.94
RELEASE-0.11.99

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-2923.json"