Out-of-bounds Read Affecting freexl package, versions >=0.0.0


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.51% (78th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-COCOAPODS-FREEXL-470692
  • published2 Oct 2019
  • disclosed23 Feb 2018
  • creditUnknown

Introduced: 23 Feb 2018

CVE-2018-7438  (opens in a new tab)
CWE-119  (opens in a new tab)

How to fix?

There is no fixed version for freexl.

Overview

freexl is an open source library to extract valid data from within an Excel (.xls) spreadsheet.

Affected versions of this package are vulnerable to Out-of-bounds Read. The vulnerability exists in the parse_unicode_string of freexl.c where it is possible for a heap-based buffer over-read to occur which has the potential to cause Denial of Service (DoS)

CVSS Scores

version 3.1