Security Advisories (1)
CVE-2023-7101 (2023-12-24)

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.

Changes for version 0.22.1

  • Mod ParseExcel : Fix Continue (COTINUE with no header) (Thank you, Steve Sapovits) : Fix Hidden RowHeight, ColWidht (Thank you, Maxim Ovchinnikov) : Fix ignore Graph sheet (Thank you, Joel Defarge )
  • Mod Utility : Fix eval at Conditiona-Format (Thank you, Alok K. Dhir)
  • Add sample/dumpHTHML.pl (Thank you, Jean-Marc Vanel)

Modules

Get information from Excel file UNAUTHORIZED
Expand of Spreadsheet::ParseExcel with Spreadsheet::WriteExcel
Utility function for Spreadsheet::ParseExcel

Provides

in ParseExcel/Dump.pm
in ParseExcel/FmtDefault.pm
in ParseExcel/FmtJapan.pm
in ParseExcel/FmtJapan2.pm
in ParseExcel/FmtUnicode.pm
in ParseExcel/SaveParser.pm