Title: xlreader book_format_sql() Function XLS Document Overflow
Info
Disclosure
Dec 17, 2004
Discovery
Dec 15, 2004
Dates
Exploit
Dec 15, 2004
Solution
Unknown
Description
A remote overflow exists in xlreader. xlreader fails to properly append strings to an internal array when processing an Excel document resulting in a buffer overflow. With a specially crafted request, an attacker can cause execution resulting in a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.