Description
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to version 0.66
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3702-1 | libspreadsheet-parseexcel-perl security update |
Debian DSA |
DSA-5592-1 | libspreadsheet-parseexcel-perl security update |
Ubuntu USN |
USN-6781-1 | Spreadsheet::ParseExcel vulnerability |
References
History
Tue, 21 Oct 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 13 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic. | Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic. |
Status: PUBLISHED
Assigner: Mandiant
Published:
Updated: 2025-10-21T23:05:29.481Z
Reserved: 2023-12-24T16:23:02.000Z
Link: CVE-2023-7101
Updated: 2024-08-02T08:50:08.227Z
Status : Analyzed
Published: 2023-12-24T22:15:07.983
Modified: 2025-10-24T16:39:52.043
Link: CVE-2023-7101
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN