Multiple vulnerabilities have been found in FreeXL, the worst of which could result in a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202007-44 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: FreeXL: Multiple vulnerabilities Date: July 27, 2020 Bugs: #648700 ID: 202007-44 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in FreeXL, the worst of which could result in a Denial of Service condition. Background ========= FreeXL is an open source library to extract valid data from within an Excel (.xls) spreadsheet. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/freexl < 1.0.5 > = 1.0.5 Description ========== Multiple vulnerabilities have been discovered in FreeXL. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All FreeXL users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/freexl-1.0.5" References ========= [ 1 ] CVE-2018-7435 https://nvd.nist.gov/vuln/detail/CVE-2018-7435 [ 2 ] CVE-2018-7436 https://nvd.nist.gov/vuln/detail/CVE-2018-7436 [ 3 ] CVE-2018-7437 https://nvd.nist.gov/vuln/detail/CVE-2018-7437 [ 4 ] CVE-2018-7438 https://nvd.nist.gov/vuln/detail/CVE-2018-7438 [ 5 ] CVE-2018-7439 https://nvd.nist.gov/vuln/detail/CVE-2018-7439 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202007-44 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Fixes several heap-buffer-overflows, see related Bugzilla tickets!. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-62268d69c9 2018-04-15 02:32:41.335665 --------------------------------------------------------------------------------Name : freexl Product : Fedora 28 Version : 1.0.5 Release : 1.fc28 URL : Summary : Library to extract data from within an Excel spreadsheet Description : FreeXL is a library to extract valid data from within an Excel spreadsheet (.xls) Design goals: * simple and lightweight * stable, robust and efficient * easily and universally portable * completely ignore any GUI-related oddity --------------------------------------------------------------------------------Update Information: Fixes several heap-buffer-overflows, see related Bugzilla tickets! --------------------------------------------------------------------------------References: [ 1 ] Bug #1547879 - heap-buffer-overflow in freexl::destroy_cell of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547879 [ 2 ] Bug #1547883 - heap-buffer-overflow in freexl.c:1805 parse_SST parse_SST https://bugzilla.redhat.com/show_bug.cgi?id=1547883 [ 3 ] Bug #1547885 - heap-buffer-overflow in freexl.c:1866 parse_SST of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547885 [ 4 ] Bug #1547889 - heap-buffer-overflow in freexl.c:383 parse_unicode_string of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547889 [ 5 ] Bug #1547892 - heap-buffer-overflow in freexl.c:3912 read_mini_biff_next_record of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547892 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade freexl' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Fixes several heap-buffer-overflows, see related Bugzilla tickets!. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-2eb691e7d7 2018-03-06 17:17:51.856240 --------------------------------------------------------------------------------Name : freexl Product : Fedora 27 Version : 1.0.5 Release : 1.fc27 URL : Summary : Library to extract data from within an Excel spreadsheet Description : FreeXL is a library to extract valid data from within an Excel spreadsheet (.xls) Design goals: * simple and lightweight * stable, robust and efficient * easily and universally portable * completely ignore any GUI-related oddity --------------------------------------------------------------------------------Update Information: Fixes several heap-buffer-overflows, see related Bugzilla tickets! --------------------------------------------------------------------------------References: [ 1 ] Bug #1547892 - heap-buffer-overflow in freexl.c:3912 read_mini_biff_next_record of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547892 [ 2 ] Bug #1547889 - heap-buffer-overflow in freexl.c:383 parse_unicode_string of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547889 [ 3 ] Bug #1547885 - heap-buffer-overflow in freexl.c:1866 parse_SST of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547885 [ 4 ] Bug #1547883 - heap-buffer-overflow in freexl.c:1805 parse_SST parse_SST https://bugzilla.redhat.com/show_bug.cgi?id=1547883 [ 5 ] Bug #1547879 - heap-buffer-overflow in freexl::destroy_cell of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547879 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade freexl' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Fixes several heap-buffer-overflows, see related Bugzilla tickets!. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-2eb691e7d7 2018-03-06 17:17:51.856240 --------------------------------------------------------------------------------Name : freexl Product : Fedora 27 Version : 1.0.5 Release : 1.fc27 URL : Summary : Library to extract data from within an Excel spreadsheet Description : FreeXL is a library to extract valid data from within an Excel spreadsheet (.xls) Design goals: * simple and lightweight * stable, robust and efficient * easily and universally portable * completely ignore any GUI-related oddity --------------------------------------------------------------------------------Update Information: Fixes several heap-buffer-overflows, see related Bugzilla tickets! --------------------------------------------------------------------------------References: [ 1 ] Bug #1547892 - heap-buffer-overflow in freexl.c:3912 read_mini_biff_next_record of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547892 [ 2 ] Bug #1547889 - heap-buffer-overflow in freexl.c:383 parse_unicode_string of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547889 [ 3 ] Bug #1547885 - heap-buffer-overflow in freexl.c:1866 parse_SST of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547885 [ 4 ] Bug #1547883 - heap-buffer-overflow in freexl.c:1805 parse_SST parse_SST https://bugzilla.redhat.com/show_bug.cgi?id=1547883 [ 5 ] Bug #1547879 - heap-buffer-overflow in freexl::destroy_cell of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547879 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade freexl' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Fixes several heap-buffer-overflows, see related Bugzilla tickets!. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-5573046c3b 2018-03-06 17:26:39.511112 --------------------------------------------------------------------------------Name : freexl Product : Fedora 26 Version : 1.0.5 Release : 1.fc26 URL : Summary : Library to extract data from within an Excel spreadsheet Description : FreeXL is a library to extract valid data from within an Excel spreadsheet (.xls) Design goals: * simple and lightweight * stable, robust and efficient * easily and universally portable * completely ignore any GUI-related oddity --------------------------------------------------------------------------------Update Information: Fixes several heap-buffer-overflows, see related Bugzilla tickets! --------------------------------------------------------------------------------References: [ 1 ] Bug #1547892 - heap-buffer-overflow in freexl.c:3912 read_mini_biff_next_record of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547892 [ 2 ] Bug #1547889 - heap-buffer-overflow in freexl.c:383 parse_unicode_string of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547889 [ 3 ] Bug #1547885 - heap-buffer-overflow in freexl.c:1866 parse_SST of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547885 [ 4 ] Bug #1547883 - heap-buffer-overflow in freexl.c:1805 parse_SST parse_SST https://bugzilla.redhat.com/show_bug.cgi?id=1547883 [ 5 ] Bug #1547879 - heap-buffer-overflow in freexl::destroy_cell of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547879 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade freexl' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Fixes several heap-buffer-overflows, see related Bugzilla tickets!. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-5573046c3b 2018-03-06 17:26:39.511112 --------------------------------------------------------------------------------Name : freexl Product : Fedora 26 Version : 1.0.5 Release : 1.fc26 URL : Summary : Library to extract data from within an Excel spreadsheet Description : FreeXL is a library to extract valid data from within an Excel spreadsheet (.xls) Design goals: * simple and lightweight * stable, robust and efficient * easily and universally portable * completely ignore any GUI-related oddity --------------------------------------------------------------------------------Update Information: Fixes several heap-buffer-overflows, see related Bugzilla tickets! --------------------------------------------------------------------------------References: [ 1 ] Bug #1547892 - heap-buffer-overflow in freexl.c:3912 read_mini_biff_next_record of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547892 [ 2 ] Bug #1547889 - heap-buffer-overflow in freexl.c:383 parse_unicode_string of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547889 [ 3 ] Bug #1547885 - heap-buffer-overflow in freexl.c:1866 parse_SST of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547885 [ 4 ] Bug #1547883 - heap-buffer-overflow in freexl.c:1805 parse_SST parse_SST https://bugzilla.redhat.com/show_bug.cgi?id=1547883 [ 5 ] Bug #1547879 - heap-buffer-overflow in freexl::destroy_cell of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547879 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade freexl' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Multiple heap buffer over reads were discovered in freexl, a library to read Microsoft Excel spreadsheets, which could result in denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4129-1
An update that fixes 5 vulnerabilities is now available.. openSUSE Security Update: Security update for freexl ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:0570-1 Rating: important References: #1082774 #1082775 #1082776 #1082777 #1082778 Cross-References: CVE-2018-7435 CVE-2018-7436 CVE-2018-7437 CVE-2018-7438 CVE-2018-7439 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for freexl fixes the following issues: freexl was updated to version 1.0.5: * No changelog provided by upstream * Various heapoverflows in 1.0.4 have been fixed: * CVE-2018-7439: heap-buffer-overflow in freexl.c:3912 read_mini_biff_next_record (boo#1082774) * CVE-2018-7438: heap-buffer-overflow in freexl.c:383 parse_unicode_string (boo#1082775) * CVE-2018-7437: heap-buffer-overflow in freexl.c:1866 parse_SST(boo#1082776) * CVE-2018-7436: heap-buffer-overflow in freexl.c:1805 parse_SST parse_SST (boo#1082777) * CVE-2018-7435: heap-buffer-overflow in freexl::destroy_cell (boo#1082778) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-217=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.3 (i586 x86_64): freexl-debugsource-1.0.5-8.1 freexl-devel-1.0.5-8.1 libfreexl1-1.0.5-8.1 libfreexl1-debuginfo-1.0.5-8.1 References: https://www.suse.com/security/cve/CVE-2018-7435.html https://www.suse.com/security/cve/CVE-2018-7436.html https://www.suse.com/security/cve/CVE-2018-7437.html https://www.suse.com/security/cve/CVE-2018-7438.html https://www.suse.com/security/cve/CVE-2018-7439.html https://bugzilla.suse.com/1082774 https://bugzilla.suse.com/1082775 https://bugzilla.suse.com/1082776 https://bugzilla.suse.com/1082777 https://bugzilla.suse.com/1082778 -- . A crucial security patch for openSUSE freexl addresses 5 severe vulnerabilities. Find patch specifics and upgrade guidelines here.. openSUSE Security Update, freexl Critical Issues, Heap Overflow Fixes. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.