Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-3702-1 | libspreadsheet-parseexcel-perl security update |
![]() |
DSA-5592-1 | libspreadsheet-parseexcel-perl security update |
![]() |
USN-6781-1 | Spreadsheet::ParseExcel vulnerability |
Fixes
Solution
Update to version 0.66
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Feb 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic. | Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic. |

Status: PUBLISHED
Assigner: Mandiant
Published:
Updated: 2025-08-20T03:56:13.214Z
Reserved: 2023-12-24T16:23:02.000Z
Link: CVE-2023-7101

Updated: 2024-08-02T08:50:08.227Z

Status : Modified
Published: 2023-12-24T22:15:07.983
Modified: 2025-02-13T18:16:12.690
Link: CVE-2023-7101

No data.

No data.