CVE-2020-27819

NameCVE-2020-27819
DescriptionAn issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer dereference vulnerability exists when parsing XLS cells in libxls/xls2csv.c:199. It could allow a remote attacker to cause a denial of service via crafted XLS file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
r-cran-readxl (PTS)stretch0.1.1-1+deb9u2fixed
stretch (security), stretch (lts)0.1.1-1+deb9u1fixed
buster1.3.0-1fixed
bullseye1.3.1-2fixed
bookworm1.4.2-1fixed
sid, trixie1.4.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
r-cran-readxlsource(unstable)(not affected)

Notes

- r-cran-readxl <not-affected> (Embeds libxls, but not affected)
https://github.com/libxls/libxls/issues/84

Search for package or bug name: Reporting problems