Alerts This Week
Warning Icon 1 640
Alerts This Week
Warning Icon 1 640

Ubuntu 23.10 USN-6769-1 High: libspreadsheet-parsexlsx-perl Memory Issues

ubuntu
Calendar Grey May 9, 2024
Dist Ubuntu Esm H88
Ubuntu security updates resolve critical issues in libspreadsheet-parsexlsx-perl across multiple versions released for LTS.
Several security issues were fixed in libspreadsheet-parsexlsx-perl.

Summary

Several security issues were fixed in libspreadsheet-parsexlsx-perl.

Software Description:

- libspreadsheet-parsexlsx-perl: Perl module to parse XLSX files

Details:

Le Dinh Hai discovered that Spreadsheet::ParseXLSX did not properly manage

memory during cell merge operations. An attacker could possibly use this

issue to consume large amounts of memory, resulting in a denial of service

condition. (CVE-2024-22368)

An Pham discovered that Spreadsheet::ParseXLSX allowed the processing of

external entities in a default configuration. An attacker could possibly

use this vulnerability to execute an XML External Entity (XXE) injection

attack. (CVE-2024-23525)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10
   libspreadsheet-parsexlsx-perl   0.27-3+deb12u2build0.23.10.1

Ubuntu 22.04 LTS
   libspreadsheet-parsexlsx-perl   0.27-2.1+deb11u2build0.22.04.1

Ubuntu 20.04 LTS
   libspreadsheet-parsexlsx-perl   0.27-2+deb10u1build0.20.04.1

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-6769-1

  CVE-2024-22368, CVE-2024-23525

Ubuntu Security Notice USN-6769-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here