Security Advisories (1)
CVE-2023-7101 (2023-12-24)

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.

Changes for version 0.31

  • Require IO::Scalar always as OLE::Storage_Lite needs it but does not prereq it
  • disable some of the tests that don't yet work on 64 bit due to number precision in order to allow automatic installation

Modules

Get information from Excel file UNAUTHORIZED
Expand of Spreadsheet::ParseExcel with Spreadsheet::WriteExcel UNAUTHORIZED
Utility function for Spreadsheet::ParseExcel UNAUTHORIZED

Provides

in lib/Spreadsheet/ParseExcel.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/Dump.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/FmtDefault.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/FmtJapan.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/FmtJapan2.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/FmtUnicode.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/SaveParser.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel/SaveParser.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel.pm UNAUTHORIZED
in lib/Spreadsheet/ParseExcel.pm UNAUTHORIZED