The U.S. Cybersecurity and Infrastructure Security Agency has added two vulnerabilities to the Known Exploited Vulnerabilities catalog, a recently patched flaw in Google Chrome and a bug affecting an open-source Perl library for reading information in an Excel file called Spreadsheet::ParseExcel. America's cyber defense agency has given federal agencies until January 23 to mitigate the two security issues tracked as CVE-2023-7024 and CVE-2023-7101 according to vendor instructions or to stop using the vulnerable products. The first issue that CISA added to its Known Exploited Vulnerabilities (KEV) is CVE-2023-7101, a remote code execution vulnerability that affects versions 0.65 and older of the Spreadsheet::ParseExcel library. “Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval.” Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic," reads CISA's description of the flaw. Spreadsheet::ParseExcel is a general-purpose library that allows data import/export operations on Excel files, run analysis and automation scripts. The product also provides a compatibility layer for Excel file processing on Perl-based web apps. One product using the open-source library is Barracuda ESG (Email Security Gateway), which has been targeted in late December by Chinese hackers who exploited the CVE-2023-7101 in Spreadsheet::ParseExcel to compromise applianc...
CISA warns of actively exploited bugs in Chrome and Excel parsing library
BleepingComputer
·Bill Toulas
·Published Jan 3, 2024
·Updated
Affected Software
2 affected components
Google Chrome=120.0.6099.129/130
Spreadsheet::ParseExcel Spreadsheet::ParseExcel=0.65
Frequently Asked Questions
1
What vulnerabilities are discussed in the article?
The article discusses recently patched vulnerabilities in Google Chrome and the Spreadsheet::ParseExcel library.
2
Who issued the warning about the vulnerabilities?
The warning was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
3
What versions of Chrome are affected by the vulnerabilities?
The affected versions of Google Chrome are 120.0.6099.129 and 120.0.6099.130.
4
What specific bug affects the Spreadsheet::ParseExcel library?
The article highlights a bug in the open-source Perl library Spreadsheet::ParseExcel version 0.65.
5
Are there any known exploits for these vulnerabilities?
Yes, both vulnerabilities have been added to the Known Exploited Vulnerabilities catalog, indicating they are actively being exploited.