Your message dated Sun, 31 Dec 2023 22:02:08 +0000
with message-id <[email protected]>
and subject line Bug#1059450: fixed in libspreadsheet-parseexcel-perl 
0.6500-4~deb12u1
has caused the Debian Bug report #1059450,
regarding libspreadsheet-parseexcel-perl: CVE-2023-7101
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1059450: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059450
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libspreadsheet-parseexcel-perl
Version: 0.6500-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 0.6500-1.1
Control: found -1 0.6500-1
Control: affects -1 + libspreadsheet-parsexlsx-perl

Hi,

The following vulnerability was published for libspreadsheet-parseexcel-perl.
The writeup[2] contains a descrption of the issue and pocs. Note that
the issue in Spreadsheet::ParseExcel will affect as well
Spreadsheet::ParseXLSX relying on Spreadsheet::ParseExcel but AFAIU,
the issue needs to be fixed in Spreadsheet::ParseExcel.

CVE-2023-7101[0]:
| Spreadsheet::ParseExcel version 0.65 is a Perl module used for
| parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an
| arbitrary code execution (ACE) vulnerability due to passing
| unvalidated input from a file into a string-type “eval”.
| Specifically, the issue stems from the evaluation of Number format
| strings (not to be confused with printf-style format strings) within
| the Excel parsing logic.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-7101
    https://www.cve.org/CVERecord?id=CVE-2023-7101
[1] https://github.com/haile01/perl_spreadsheet_excel_rce_poc

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: libspreadsheet-parseexcel-perl
Source-Version: 0.6500-4~deb12u1
Done: Salvatore Bonaccorso <[email protected]>

We believe that the bug you reported is fixed in the latest version of
libspreadsheet-parseexcel-perl, which is due to be installed in the Debian FTP 
archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated 
libspreadsheet-parseexcel-perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 30 Dec 2023 13:54:23 +0100
Source: libspreadsheet-parseexcel-perl
Architecture: source
Version: 0.6500-4~deb12u1
Distribution: bookworm-security
Urgency: high
Maintainer: Debian Perl Group <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 1059450
Changes:
 libspreadsheet-parseexcel-perl (0.6500-4~deb12u1) bookworm-security; 
urgency=high
 .
   * Team upload.
   * Rebuild for bookworm-security
 .
 libspreadsheet-parseexcel-perl (0.6500-4) unstable; urgency=medium
 .
   * Team upload.
   * Do not use string eval for conditional formatting (CVE-2023-7101)
     (Closes: #1059450)
Checksums-Sha1: 
 1eec241b557cbf08994c8daaecb44273b0e7ab37 2819 
libspreadsheet-parseexcel-perl_0.6500-4~deb12u1.dsc
 76f49a87bffcbe0191117493c69017cf6a0598da 206923 
libspreadsheet-parseexcel-perl_0.6500.orig.tar.gz
 9d4191b1e13926e1f4ee7f46b3d30ffba7fa2d35 7240 
libspreadsheet-parseexcel-perl_0.6500-4~deb12u1.debian.tar.xz
Checksums-Sha256: 
 a5919f098fc4f9055d46855853681c3f50ec3b563f1392cd8048448848d5cd2d 2819 
libspreadsheet-parseexcel-perl_0.6500-4~deb12u1.dsc
 6ec4cb429bd58d81640fe12116f435c46f51ff1040c68f09cc8b7681c1675bec 206923 
libspreadsheet-parseexcel-perl_0.6500.orig.tar.gz
 0b77363da805a2d2a34af3c0a1a78a635d63048e63bb02bf4fd5259e71fc045b 7240 
libspreadsheet-parseexcel-perl_0.6500-4~deb12u1.debian.tar.xz
Files: 
 38d70e67f2b009c7597ce9d0a75e72f0 2819 perl optional 
libspreadsheet-parseexcel-perl_0.6500-4~deb12u1.dsc
 4b8857e3a391d86501c1b742b459ac9e 206923 perl optional 
libspreadsheet-parseexcel-perl_0.6500.orig.tar.gz
 8d2d9e584294a22519c5ba6a6320c52c 7240 perl optional 
libspreadsheet-parseexcel-perl_0.6500-4~deb12u1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmWQE45fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EoY4P/0GFZtAEa+IWnjme5c5d2ByRY46PMu9U
TNftrNNKacpFekw5Y9CS3/9vM31hXpLHcU+vMcmCw31SAmcqe/+eRrww5/4L9amp
D8OqJ5uwtYOAwx70FfKjsg9NOnffkippU+vREQTzIr/YP2ZQuUZxa4pZuLeHhqho
YtHc+yodLUJ0C5pin1hM/Tb4RPq9LC+1OG3B00J3dHBvZ+UYfpLwZFD564YyQ8aK
XzJH2RVAASqhPqjb5GO5qv0CWMjC1hJjVzLHHj4J6WTxxG9+46ZlofehOZoUggdv
+UbNngaUX2mh85gIsnPpwqmlg6ZkyU2tYE957n7QbBZYlpib+cfL7+CPvyY4Dk4S
5qaL8RHSqTv8PACqsCJSJgYn90SRhM7ilPS1/6y1uMiCktOPuKnMwDXwOhbOq0yh
lou4X8ZjCy1XFfdo1Zq0XPuPkpLqSTBpgieM5IVJ3GUIocqijIVbHnog1/iBGH8j
xbcs+MXHwUvD9fy1xKztSa1uP1tbeSxXxfiolNrmUA9/Cnvbzf9Bb0z+QNIUR//W
ujWnZsmIvaxlTqP0yMnLXaV+iIscVEyIFHVZpnM6LfPIxLVchB/TqBKrFK/wY1YO
Kco0kkTt0MdP0UoZTZgM7xbm0+ChVDyD6wayaHGmK6b5Jq/fcNIMMqTgmEo9aRv4
WPVhT8qEt7Yc
=a8du
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to