EUVD-2023-59285
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 2 Jan 2024. Evidence sources: cisa_kev.
- ENISA score
- 7.8 · CVSS 3.1
- Advisory evidence
- 3 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_suse · SUSE-SU-2024:0158-1Security update for perl-Spreadsheet-ParseExcel
