Security Advisories (1)
CVE-2023-7101 (2023-12-24)

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.

Changes for version 0.30

  • add some more tests
  • add test to see memory leak using Proc::ProcessTable
  • Start using Scalar::Util qw(weaken) to (hopefully) avoid memory leak
  • It seems we did not check correctly if PERLIO is available in Makefile.PL now it is the same test we do in the code itself.
  • Flag1904 renamed to Flg1904 in documentation (Chad) RT #24293

Modules

Get information from Excel file UNAUTHORIZED
Expand of Spreadsheet::ParseExcel with Spreadsheet::WriteExcel UNAUTHORIZED
Utility function for Spreadsheet::ParseExcel UNAUTHORIZED

Provides

in lib/Spreadsheet/ParseExcel.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/Dump.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/FmtDefault.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/FmtJapan.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/FmtJapan2.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/FmtUnicode.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/SaveParser.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/SaveParser.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel.pm UNAUTHORIZED