RSEC-2023-9

See a problem?
Import Source
https://github.com/RConsortium/r-advisory-database/blob/main/vulns/gdata/RSEC-2023-9.yaml
JSON Data
https://api.osv.dev/v1/vulns/RSEC-2023-9
Aliases
Published
2023-12-28T02:15:00Z
Modified
2024-01-04T16:41:35.876798Z
Summary
Arbitrary Code Execution (ACE) Vulnerability
Details

Bundled Perl script Spreadsheet::ParseExcel version 0.65 is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type "eval". Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic. Fixed with the depreation of Excel-related functionality from gdata version 3.0.0 -- upgrading advised.

References

Affected packages

CRAN / gdata

Package

Name
gdata

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.16.1
Fixed
3.0.0

Affected versions

2.*

2.16.1
2.17.0
2.18.0
2.18.0.1
2.19.0