Spreadsheet-ParseExcel Security Update Advisory (CVE-2023-7101)

Overview

An update has been made available to address an arbitrary code execution vulnerability in the Perl module used by Spreadsheet::ParseExcel(https://github.com/jmcnamara/spreadsheet-parseexcel) when parsing Excel files. Users of affected versions are advised to update to the latest version.

 

 

Affected Products

Spreadsheet::ParseExcel 0.65 and earlier versions

 

Resolved Vulnerabilities

Arbitrary code execution vulnerability in the Perl module used when parsing Excel files in Spreadsheet::ParseExcel (CVE-2023-7101)

 

Vulnerability Patches

A vulnerability patch was made available in the December 29, 2023 update. Please follow the instructions on the reference site for each operating system that uses Spreadsheet::ParseExcel to update to the latest version.

Spreadsheet::ParseExcel version 0.66

 

Referenced Sites

[1] https://www.cve.org/CVERecord?id=CVE-2023-7101

[2] https://metacpan.org/release/JMCNAMARA/Spreadsheet-ParseExcel-0.66