new release: FreeXL 1.0.5 (security fix)

17 views
Skip to first unread message

Alessandro Furieri

unread,
Feb 22, 2018, 10:27:06 AM2/22/18
to SpatiaLite Users
Hi list,

few more vulnerabilities affecting FreeXL have been recently 
discovered; for more details please check Red Hat Bugzilla
Bug 1547879

all reported vulnerabilities are never expected to be encountered 
when reading valid XLS files, and can only affect purposely crafted 
files intended to maliciously trigger some nasty security breach.

the new patched version (FreeXL-1.0.5) sanes any known security
issue.


developers and system packagers are warmly invited to quickly
adopt FreeXL-1.0.5

note
========
a new error code (FREEXL_CRAFTED_FILE) has been added to FreeXL,
and it will be returned when a supposed XLS document contains
"impossible values" (not compatible with the XLS specifications),
thus leading to a legitimate suspect of a purposely crafted file.

bye Sandro
Reply all
Reply to author
Forward
0 new messages