{"id":"openSUSE-SU-2017:2539-1","summary":"Security update for freexl","details":"This update for freexl to version 1.0.4 fixes several issues.\n\nThese security issues were fixed:\n\n- CVE-2017-2924: Prevent heap-based buffer overflow in the read_legacy_biff function (bsc#1058433).\n- CVE-2017-2923: Prevent heap-based buffer overflow in the read_biff_next_record function (bsc#1058431).\n","modified":"2026-01-30T02:14:16.093712Z","published":"2017-09-21T06:52:21Z","related":["CVE-2017-2923","CVE-2017-2924"],"upstream":["CVE-2017-2923","CVE-2017-2924"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1058431"},{"type":"REPORT","url":"https://bugzilla.suse.com/1058433"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2924"}],"affected":[{"package":{"name":"freexl","ecosystem":"SUSE:Package Hub 12","purl":"pkg:rpm/suse/freexl&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.4-5.1"}]}],"ecosystem_specific":{"binaries":[{"freexl-devel":"1.0.4-5.1","libfreexl1":"1.0.4-5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2017:2539-1.json"}}],"schema_version":"1.7.3"}