Back to Database
Status published
High
CVE-2017-12110
An exploitable integer overflow vulnerability exists in the xls_appendSST function...
Vulnerability Description
An exploitable integer overflow vulnerability exists in the xls_appendSST function of libxls 1.4.A specially crafted XLS file can cause memory corruption resulting in remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-12110
Credits & Attribution
No credits recorded in the NVD database.
References
More from libxls
View All →CVE-2017-2919
An exploitable stack based buffer overflow vulnerability exists in the...
High
8.8
CVE-2017-2897
An exploitable out-of-bounds write vulnerability exists in the read_MSAT function...
High
8.8
CVE-2017-2896
An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function...
High
8.8
CVE-2017-12111
An exploitable out-of-bounds vulnerability exists in the xls_addCell function of...
High
8.8
CVE-2017-12109
An exploitable integer overflow vulnerability exists in the xls_preparseWorkSheet function...
High
8.8
Affected Vendor
libxls
View all reports →Affected Software
libxls
Vulnerable Versions:
1.4
Timeline
Official Publish:
November 20th, 2017
Last Modified:
September 17th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.