Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3702-1 | libspreadsheet-parseexcel-perl security update |
Debian DSA |
DSA-5592-1 | libspreadsheet-parseexcel-perl security update |
Ubuntu USN |
USN-6781-1 | Spreadsheet::ParseExcel vulnerability |
Fixes
Solution
Update to version 0.66
Workaround
No workaround given by the vendor.
References
History
Tue, 21 Oct 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 13 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic. | Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic. |
Status: PUBLISHED
Assigner: Mandiant
Published:
Updated: 2025-10-21T23:05:29.481Z
Reserved: 2023-12-24T16:23:02.000Z
Link: CVE-2023-7101
Updated: 2024-08-02T08:50:08.227Z
Status : Analyzed
Published: 2023-12-24T22:15:07.983
Modified: 2025-10-24T16:39:52.043
Link: CVE-2023-7101
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN