VYPR
Medium severity6.5OSV Advisory· Published Dec 25, 2018· Updated Jun 17, 2026

CVE-2018-20450

CVE-2018-20450

Description

The read_MSAT function in ole.c in libxls 1.4.0 has a double free that allows attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2017-2897.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Libxls/LibxlsOSV3 versions
    v0.2.0, v0.3.0, v1.0.0, …+ 2 more
    • (no CPE)range: v0.2.0, v0.3.0, v1.0.0, …
    • cpe:2.3:a:libxls_project:libxls:1.4.0:*:*:*:*:*:*:*
    • (no CPE)range: =1.4.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.