Arbitrary Code Injection Affecting libspreadsheet-parseexcel-perl package, versions <0.6500-4


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

Exploit Maturity
Attacked
EPSS
19.11% (98th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-LIBSPREADSHEETPARSEEXCELPERL-6139279
  • published25 Dec 2023
  • disclosed24 Dec 2023

Introduced: 24 Dec 2023

CVE-2023-7101  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

Upgrade Debian:unstable libspreadsheet-parseexcel-perl to version 0.6500-4 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libspreadsheet-parseexcel-perl package and not the libspreadsheet-parseexcel-perl package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.

CVSS Base Scores

version 3.1