Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 39: FEDORA-2023-921f6975c2 critical: perl-Spreadsheet exec risk

fedora
Calendar Grey January 8, 2024
Dist Fedora Esm H88
Fedora 39 contains a flaw within the Spreadsheet-ParseExcel library that may permit arbitrary code execution.
Fix for CVE-2023-7101 (unvalidated input can lead to arbitrary code execution vulnerability).

Summary

The Spreadsheet::ParseExcel module can be used to read information from an

Excel 95-2003 file.

Update Information:

Fix for CVE-2023-7101 (unvalidated input can lead to arbitrary code execution vulnerability).

Change Log

* Sat Dec 30 2023 Paul Howarth - 0.6600-1 - Update to 0.66 - Fix for CVE-2023-7101 (unvalidated input can lead to arbitrary code execution vulnerability) https://github.com/runrig/spreadsheet-parseexcel/issues/33 - Use author-independent source URL - Use SPDX-format license tag - No longer need to fix document file permissions - Fix permissions verbosely - Don't assume "pm" suffix on manpage files

References


[ 1 ] Bug #2255871 - CVE-2023-7101 perl-Spreadsheet-ParseExcel: unvalidated input can lead to arbitrary code execution vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2255871

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-921f6975c2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: perl-Spreadsheet-ParseExcel
Product: Fedora 39
Version: 0.6600
Release: 1.fc39
Summary: Extract information from an Excel file

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here