Hi list,
few more vulnerabilities affecting FreeXL have been recently
discovered; for more details please check Red Hat Bugzilla
Bug 1547879
all reported vulnerabilities are never expected to be encountered
when reading valid XLS files, and can only affect purposely crafted
files intended to maliciously trigger some nasty security breach.
the new patched version (FreeXL-1.0.5) sanes any known security
issue.
developers and system packagers are warmly invited to quickly
adopt FreeXL-1.0.5
note
========
a new error code (FREEXL_CRAFTED_FILE) has been added to FreeXL,
and it will be returned when a supposed XLS document contains
"impossible values" (not compatible with the XLS specifications),
thus leading to a legitimate suspect of a purposely crafted file.
bye Sandro