CVE-2023-7101: Arbitrary Code Execution (ACE) Vulnerability
Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.
Other sources
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.
— Ubuntu
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libspreadsheet-parseexcel-perlto a version that resolves this vulnerability.Fixed in 0.6500-1+deb10u1Fixed in 0.6500-1.1+deb11u1Fixed in 0.6500-4~deb12u1Fixed in 0.6600-1 - Upgrade
Upgrade
ubuntu/libspreadsheet-parseexcel-perlto a version that resolves this vulnerability.Fixed in 0.6500-1ubuntu0.18.04.1~ - Upgrade
Upgrade
ubuntu/libspreadsheet-parseexcel-perlto a version that resolves this vulnerability.Fixed in 0.6500-1ubuntu0.20.04.1 - Upgrade
Upgrade
ubuntu/libspreadsheet-parseexcel-perlto a version that resolves this vulnerability.Fixed in 0.6500-1.1ubuntu0.1 - Upgrade
Upgrade
ubuntu/libspreadsheet-parseexcel-perlto a version that resolves this vulnerability.Fixed in 0.5800-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/libspreadsheet-parseexcel-perlto a version that resolves this vulnerability.Fixed in 0.6500-4 - Upgrade
Upgrade
ubuntu/libspreadsheet-parseexcel-perlto a version that resolves this vulnerability.Fixed in 0.6500-1ubuntu0.16.04.1~ - Upgrade
Upgrade
Spreadsheet::ParseExcelto a version that resolves this vulnerability.Fixed in 0.66 - Upgrade
Upgrade
debian/libspreadsheet-parseexcel-perlto a version that resolves this vulnerability.Fixed in 0.6500-1+deb10u1 - Upgrade
Upgrade
debian/libspreadsheet-parseexcel-perlto a version that resolves this vulnerability.Fixed in 0.6500-1.1+deb11u1 - Upgrade
Upgrade
debian/libspreadsheet-parseexcel-perlto a version that resolves this vulnerability.Fixed in 0.6500-4~deb12u1 - Upgrade
Upgrade
debian/libspreadsheet-parseexcel-perlto a version that resolves this vulnerability.Fixed in 0.6600-1
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7101?
CVE-2023-7101 has a critical severity due to the potential for remote code execution.
How do I fix CVE-2023-7101?
To fix CVE-2023-7101, upgrade Spreadsheet::ParseExcel to version 0.66 or later.
Which versions of Spreadsheet::ParseExcel are affected by CVE-2023-7101?
CVE-2023-7101 affects versions up to 0.65 of Spreadsheet::ParseExcel.
Can CVE-2023-7101 be exploited remotely?
Yes, CVE-2023-7101 can be exploited remotely due to the nature of the vulnerability.
Is CVE-2023-7101 specific to any operating systems?
CVE-2023-7101 affects applications using Spreadsheet::ParseExcel across various operating systems, including Debian and Ubuntu.