Ubuntu Security Update USN-6769-1: Spreadsheet::ParseXLSX vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
30
Reaction score
10
Credits
0
Le Dinh Hai discovered that Spreadsheet::parseXLSX did not properly manage memory during cell merge operations. An attacker could possibly use this issue to consume large amounts of memory, resulting in a denial of service condition. (CVE-2024-22368) An Pham discovered that Spreadsheet::parseXLSX allowed the processing of external entities in a default configuration. An attacker could possibly use this vulnerability to execute an XML External Entity (XXE) injection attack. (CVE-2024-23525)

Continue reading...
 


Top