Your message dated Fri, 29 Dec 2023 09:04:06 +0000
with message-id <[email protected]>
and subject line Bug#1059450: fixed in libspreadsheet-parseexcel-perl 0.6500-4
has caused the Debian Bug report #1059450,
regarding libspreadsheet-parseexcel-perl: CVE-2023-7101
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1059450: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059450
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libspreadsheet-parseexcel-perl
Version: 0.6500-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 0.6500-1.1
Control: found -1 0.6500-1
Control: affects -1 + libspreadsheet-parsexlsx-perl

Hi,

The following vulnerability was published for libspreadsheet-parseexcel-perl.
The writeup[2] contains a descrption of the issue and pocs. Note that
the issue in Spreadsheet::ParseExcel will affect as well
Spreadsheet::ParseXLSX relying on Spreadsheet::ParseExcel but AFAIU,
the issue needs to be fixed in Spreadsheet::ParseExcel.

CVE-2023-7101[0]:
| Spreadsheet::ParseExcel version 0.65 is a Perl module used for
| parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an
| arbitrary code execution (ACE) vulnerability due to passing
| unvalidated input from a file into a string-type “eval”.
| Specifically, the issue stems from the evaluation of Number format
| strings (not to be confused with printf-style format strings) within
| the Excel parsing logic.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-7101
    https://www.cve.org/CVERecord?id=CVE-2023-7101
[1] https://github.com/haile01/perl_spreadsheet_excel_rce_poc

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: libspreadsheet-parseexcel-perl
Source-Version: 0.6500-4
Done: Salvatore Bonaccorso <[email protected]>

We believe that the bug you reported is fixed in the latest version of
libspreadsheet-parseexcel-perl, which is due to be installed in the Debian FTP 
archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated 
libspreadsheet-parseexcel-perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 29 Dec 2023 09:41:06 +0100
Source: libspreadsheet-parseexcel-perl
Architecture: source
Version: 0.6500-4
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 1059450
Changes:
 libspreadsheet-parseexcel-perl (0.6500-4) unstable; urgency=medium
 .
   * Team upload.
   * Do not use string eval for conditional formatting (CVE-2023-7101)
     (Closes: #1059450)
Checksums-Sha1: 
 babe7c11b3973ee3013d3764e58b896df2d9f7a4 2787 
libspreadsheet-parseexcel-perl_0.6500-4.dsc
 ae8dc06ee3c80c452299380115719a5c1fc0aab5 7204 
libspreadsheet-parseexcel-perl_0.6500-4.debian.tar.xz
Checksums-Sha256: 
 6b57053ff9154ee863455e049bd04c791abcb2f5155d667cafcabc38c274b133 2787 
libspreadsheet-parseexcel-perl_0.6500-4.dsc
 f01a4f81483842d3a449847a8a26907039a0e7f9061993a98851f3b6ff8176b9 7204 
libspreadsheet-parseexcel-perl_0.6500-4.debian.tar.xz
Files: 
 8dfa2b33d753777e472f1de8aca6f28a 2787 perl optional 
libspreadsheet-parseexcel-perl_0.6500-4.dsc
 6bacc37c9d4558ae70cfe850783f3416 7204 perl optional 
libspreadsheet-parseexcel-perl_0.6500-4.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmWOh8lfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EBOkQAJIZwcqWJlK7NlDWl6kVhvMcUPEm7wJl
tGKaX342rXoG0RZ/jUM1TtJi5ZrYwpTvuvAOsNEazA6+9rtzPurg8/ZL6r3eL9Tk
F2bsSiUOobLFkD7B5T9GeY2XQYWPvaL/X+XZeqTo45oAmLnbvl2Nj1NHG01NUlBj
d01zH0Vz7gfLnP+SJwwFXAUMzkKIC7vJ/G7ixmF6Q8xO2k5BvV0K+sQIUsbg4OYs
Hk+xtnBLt1gLsRrZZ7qtCkxYPhMyXrytB+Vw3O57fGBFSLtrStmOcEtYyw37OBuP
0UDLLZNoEyQqWZTwJUpuOeenSSQKZXzW7Cg9rc74K2wFhUqnMmTcW5W/PzhlJYZU
57xQvDyExRF9QltXWMuMTxE2eKkLvychhQM6KsC/ulgZ5TZC1x0MCDzA1XYkRWUo
7w+XtTa83HMJwDYYbWe3ICcKOqCXIR5g4uiy/3JhyKH1OjftOS4OHeousvzzAAN+
acrLsdAL0Ve0x/hIwFrOi/qHFAc1Mzcwj5PH0H1i0Q43lbZh4k/EKsrJixkse3WC
jiuDSgCkJkgNVzNv+85XuNDNDH2luU8dbAryMmXxgjBJncdN6rxG5KATXZ4mMoCk
QV7FA4ebQpfYYe0anzRZmUyrGU9nbM8EBrlIh7zQwqzCQIHuCXUohcJ6DDOvPO4X
oQitxcTVKF3T
=tY4q
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to