Spreadsheet::ParseExcel version 0.65 is a Perl module...
High severity
Unreviewed
Published
Dec 25, 2023
to the GitHub Advisory Database
•
Updated May 15, 2024
Description
Published by the National Vulnerability Database
Dec 24, 2023
Published to the GitHub Advisory Database
Dec 25, 2023
Last updated
May 15, 2024
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.
References