RSEC-2023-9

See a problem?
Import Source
https://github.com/RConsortium/r-advisory-database/blob/main/vulns/gdata/RSEC-2023-9.yaml
JSON Data
https://api.osv.dev/v1/vulns/RSEC-2023-9
Published
2025-05-16T00:12:44Z
Modified
2025-05-19T19:43:48.455096Z
Upstream
Summary
Arbitrary Code Execution (ACE) Vulnerability
Details

Bundled Perl script Spreadsheet::ParseExcel version 0.65 is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type "eval". Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic. Fixed with the depreation of Excel-related functionality from gdata version 3.0.0 -- upgrading advised.

References

Affected packages

CRAN / gdata

Package

Name
gdata
Purl
pkg:cran/gdata

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.16.1
Fixed
3.0.0

Affected versions

2.*

2.16.1
2.17.0
2.18.0
2.18.0.1
2.19.0