xlsxio v0.1.2 to v0.2.34 was discovered to contain a free of uninitialized pointer in the xlsxioreadsheetlistclose() function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted XLSX file.
[
{
"digest": {
"length": 1112.0,
"function_hash": "305902545275284073404997409807059961263"
},
"id": "CVE-2023-34795-64e1e53a",
"source": "https://github.com/brechtsanders/xlsxio/commit/d653f1604b54532f11b45dca1fa164b4a1f15e2d",
"signature_type": "Function",
"target": {
"file": "lib/xlsxio_read.c",
"function": "xlsxioread_sheetlist_open"
},
"signature_version": "v1",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"302690977701771854163438072249211416321",
"49738666660649064886705723745264120926",
"138260580017980920614606923562183985925",
"38231482405369132459825939103438119397"
]
},
"id": "CVE-2023-34795-7257d3e3",
"source": "https://github.com/brechtsanders/xlsxio/commit/d653f1604b54532f11b45dca1fa164b4a1f15e2d",
"signature_type": "Line",
"target": {
"file": "lib/xlsxio_read.c"
},
"signature_version": "v1",
"deprecated": false
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34795.json"