Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 38: 2023-84d3cc47b1 critical: Perl-Spreadsheet-ParseExcel input flaw

fedora
Calendar Grey January 8, 2024
Dist Fedora Esm H88
Recent improvements to perl-Spreadsheet-ParseExcel address critical input validation issues that could potentially lead to code execution vulnerabilities in Fedora environments.
Fix for CVE-2023-7101 (unvalidated input can lead to arbitrary code execution vulnerability).

Summary

The Spreadsheet::ParseExcel module can be used to read information from an

Excel 95-2003 file.

Update Information:

Fix for CVE-2023-7101 (unvalidated input can lead to arbitrary code execution vulnerability).

Change Log

* Sat Dec 30 2023 Paul Howarth - 0.6600-1 - Update to 0.66 - Fix for CVE-2023-7101 (unvalidated input can lead to arbitrary code execution vulnerability) https://github.com/runrig/spreadsheet-parseexcel/issues/33 - Use author-independent source URL - Use SPDX-format license tag - No longer need to fix document file permissions - Fix permissions verbosely - Don't assume "pm" suffix on manpage files * Fri Jul 21 2023 Fedora Release Engineering - 0.6500-35 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild

References


[ 1 ] Bug #2255871 - CVE-2023-7101 perl-Spreadsheet-ParseExcel: unvalidated input can lead to arbitrary code execution vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2255871

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-84d3cc47b1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: perl-Spreadsheet-ParseExcel
Product: Fedora 38
Version: 0.6600
Release: 1.fc38
Summary: Extract information from an Excel file

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here