CVE-2008-0668

The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer signedness error that leads to an integer overflow.  NOTE: some of these details are obtained from third party information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
gnomegnumeric
𝑥
≤ 1.7.91
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gnumeric
bullseye
1.12.48-1
fixed
bookworm
1.12.55-1
fixed
sid
1.12.57-1
fixed
trixie
1.12.57-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnumeric
gutsy
Fixed 1.7.11-1ubuntu3.1
released
feisty
Fixed 1.7.8-0ubuntu1.1
released
edgy
Fixed 1.7.0-1ubuntu4.1
released
dapper
Fixed 1.6.3-0ubuntu4.1
released
Common Weakness Enumeration
References