Security fix for CVE-2023-38852. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-8b67e47e43 2024-02-27 01:44:25.903558 -------------------------------------------------------------------------------- Name : libxls Product : Fedora 38 Version : 1.6.2 Release : 14.fc38 URL : https://github.com/libxls/libxls Summary : Read binary Excel files from C/C++ Description : This is libxls, a C library for reading Excel files in the old binary OLE format, plus a command-line tool for converting XLS to CSV (named, appropriately enough, libxls2csv). -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-38852 -------------------------------------------------------------------------------- ChangeLog: * Sun Feb 18 2024 Elliott Sales de Andrade - 1.6.2-13 - Backport fix for CVE-2023-38852 (#2232511) * Thu Jan 25 2024 Fedora Release Engineering - 1.6.2-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 1.6.2-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Thu Jul 20 2023 Fedora Release Engineering - 1.6.2-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2232479 - CVE-2023-38852 libxls: heap buffer overflow in xls_parseWorkBook() in xls.c https://bugzilla.redhat.com/show_bug.cgi?id=2232479 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-8b67e47e43' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPGkey. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Security fix for CVE-2023-38852. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-e74783429c 2024-02-27 01:07:18.072495 -------------------------------------------------------------------------------- Name : libxls Product : Fedora 39 Version : 1.6.2 Release : 14.fc39 URL : https://github.com/libxls/libxls Summary : Read binary Excel files from C/C++ Description : This is libxls, a C library for reading Excel files in the old binary OLE format, plus a command-line tool for converting XLS to CSV (named, appropriately enough, libxls2csv). -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-38852 -------------------------------------------------------------------------------- ChangeLog: * Sun Feb 18 2024 Elliott Sales de Andrade - 1.6.2-13 - Backport fix for CVE-2023-38852 (#2232511) * Thu Jan 25 2024 Fedora Release Engineering - 1.6.2-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 1.6.2-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2232479 - CVE-2023-38852 libxls: heap buffer overflow in xls_parseWorkBook() in xls.c https://bugzilla.redhat.com/show_bug.cgi?id=2232479 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-e74783429c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libxls ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0142-1 Rating: moderate References: #1192323 Cross-References: CVE-2021-27836 Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libxls fixes the following issues: - CVE-2021-27836: Fixed possible NULL pointer dereference via crafted XLS (boo#1192323) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-142=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): libxls-devel-1.6.2-bp153.2.6.1 libxls-tools-1.6.2-bp153.2.6.1 libxlsreader8-1.6.2-bp153.2.6.1 References: https://www.suse.com/security/cve/CVE-2021-27836.html https://bugzilla.suse.com/1192323 . Crucial openSUSE Security Patch for libxls tackling a medium risk vulnerability. Update classified as moderate.. openSUSE Security, libxls Vulnerability, Backports Update. . LinuxSecurity.com Team
Security fix for CVE-2021-27836. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-033a5fe9e5 2021-11-24 01:17:50.947076 --------------------------------------------------------------------------------Name : libxls Product : Fedora 35 Version : 1.6.2 Release : 5.fc35 URL : https://github.com/libxls/libxls Summary : Read binary Excel files from C/C++ Description : This is libxls, a C library for reading Excel files in the old binary OLE format, plus a command-line tool for converting XLS to CSV (named, appropriately enough, libxls2csv). --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-27836 --------------------------------------------------------------------------------ChangeLog: * Tue Nov 16 2021 Elliott Sales de Andrade 1.6.2-5 - Fix release * Tue Nov 16 2021 Elliott Sales de Andrade 1.6.2-5 - Fix CVE-2021-27836 (#2023409) --------------------------------------------------------------------------------References: [ 1 ] Bug #2023408 - CVE-2021-27836 libxls: a denial of service via a crafted XLS file https://bugzilla.redhat.com/show_bug.cgi?id=2023408 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-033a5fe9e5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2021-27836. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-785cdbddf9 2021-11-24 01:08:33.426092 --------------------------------------------------------------------------------Name : libxls Product : Fedora 34 Version : 1.6.2 Release : 5.fc34 URL : https://github.com/libxls/libxls Summary : Read binary Excel files from C/C++ Description : This is libxls, a C library for reading Excel files in the old binary OLE format, plus a command-line tool for converting XLS to CSV (named, appropriately enough, libxls2csv). --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-27836 --------------------------------------------------------------------------------ChangeLog: * Tue Nov 16 2021 Elliott Sales de Andrade 1.6.2-5 - Fix release * Tue Nov 16 2021 Elliott Sales de Andrade 1.6.2-5 - Fix CVE-2021-27836 (#2023409) * Thu Jul 22 2021 Fedora Release Engineering - 1.6.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2023408 - CVE-2021-27836 libxls: a denial of service via a crafted XLS file https://bugzilla.redhat.com/show_bug.cgi?id=2023408 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-785cdbddf9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2021-27836. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-25e89d9374 2021-11-24 01:01:29.542284 --------------------------------------------------------------------------------Name : libxls Product : Fedora 33 Version : 1.6.2 Release : 5.fc33 URL : https://github.com/libxls/libxls Summary : Read binary Excel files from C/C++ Description : This is libxls, a C library for reading Excel files in the old binary OLE format, plus a command-line tool for converting XLS to CSV (named, appropriately enough, libxls2csv). --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-27836 --------------------------------------------------------------------------------ChangeLog: * Tue Nov 16 2021 Elliott Sales de Andrade 1.6.2-5 - Fix release * Tue Nov 16 2021 Elliott Sales de Andrade 1.6.2-5 - Fix CVE-2021-27836 (#2023409) * Thu Jul 22 2021 Fedora Release Engineering - 1.6.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild * Tue Jan 26 2021 Fedora Release Engineering - 1.6.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2023408 - CVE-2021-27836 libxls: a denial of service via a crafted XLS file https://bugzilla.redhat.com/show_bug.cgi?id=2023408 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-25e89d9374' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libxls ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0812-1 Rating: moderate References: #1179532 Cross-References: CVE-2020-27819 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libxls fixes the following issues: libxsl was updated to release 1.6.2: * Fix NULL pointer dereferences in the xls2csv tool [boo#1179532] [CVE-2020-27819] Update to release 1.6.1 * Enabled decoding of non-Unicode character sets in older (BIFF5) XLS files. * Improved string conversion performance in newer files. update to 1.5.3: * Allow truncated XLS files * Fix long-standing "extra column" bug #73 * Support for RSTRING records (rich-text cells in older BIFF5 files) tidyverse/readxl#611 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-812=1 Package List: - openSUSE Leap 15.2 (x86_64): libxls-debuginfo-1.6.2-lp152.2.3.1 libxls-debugsource-1.6.2-lp152.2.3.1 libxls-devel-1.6.2-lp152.2.3.1 libxls-tools-1.6.2-lp152.2.3.1 libxls-tools-debuginfo-1.6.2-lp152.2.3.1 libxlsreader8-1.6.2-lp152.2.3.1 libxlsreader8-debuginfo-1.6.2-lp152.2.3.1 References: https://www.suse.com/security/cve/CVE-2020-27819.html https://bugzilla.suse.com/1179532 . OpenSUSE has rolled out a patch for libxls, addressing concerns and enhancing the performance of legacy XLS documents.. openSUSE Update, libxls Security Patch, Linux Fix. .LinuxSecurity.com Team
Security fix for CVE-2020-27819. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-688a51575a 2020-12-12 01:09:08.615403 --------------------------------------------------------------------------------Name : libxls Product : Fedora 32 Version : 1.5.3 Release : 3.fc32 URL : https://github.com/libxls/libxls Summary : Read binary Excel files from C/C++ Description : This is libxls, a C library for reading Excel files in the old binary OLE format, plus a command-line tool for converting XLS to CSV (named, appropriately enough, libxls2csv). --------------------------------------------------------------------------------Update Information: Security fix for CVE-2020-27819 --------------------------------------------------------------------------------ChangeLog: * Wed Dec 2 2020 Elliott Sales de Andrade - 1.5.3-3 - Fix CVE-2020-27819 * Tue Jul 28 2020 Fedora Release Engineering - 1.5.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1903296 - CVE-2020-27819 libxls: NULL pointer dereference via crafted xls file https://bugzilla.redhat.com/show_bug.cgi?id=1903296 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-688a51575a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.