The read_MSAT function in ole.c in libxls 1.4.0 has a double free that allows attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2017-2897.
{ "binaries": [ { "binary_version": "0.1.0-1", "binary_name": "r-cran-readxl" } ] }
{ "binaries": [ { "binary_version": "1.0.0-2", "binary_name": "r-cran-readxl" } ] }
{ "binaries": [ { "binary_version": "1.3.1-2build1", "binary_name": "r-cran-readxl" } ] }
{ "binaries": [ { "binary_version": "1.3.1-2build2", "binary_name": "r-cran-readxl" } ] }
{ "binaries": [ { "binary_version": "1.4.3-1", "binary_name": "r-cran-readxl" } ] }
{ "binaries": [ { "binary_version": "1.4.5-1", "binary_name": "r-cran-readxl" } ] }