Use of Potentially Dangerous Function in Spreadsheet-ParseExcel - CVE-2023-7101
Published: December 27, 2023 / Updated: May 19, 2026
Vulnerability identifier: #VU84793
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-7101
CWE-ID: CWE-676
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation when parsing Excel files. A remote attacker can pass a specially crafted file to the application and execute arbitrary code on the system.
Affected software
Spreadsheet-ParseExcel
Gentoo Linux
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Fedora
SUSE Enterprise Storage
Ubuntu
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
Anolis OS
openEuler
libspreadsheet-parseexcel-perl (Ubuntu package)
perl-Spreadsheet-ParseExcel-help
perl-Spreadsheet-ParseExcel
perl-Spreadsheet-ParseExcel-debugsource
perl-Spreadsheet-ParseExcel-debuginfo
dev-perl/Spreadsheet-ParseExcel
libspreadsheet-parseexcel-perl (Debian package)
perl-Spreadsheet-ParseExcel-doc
Tanzu Greenplum
Gentoo Linux
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Fedora
SUSE Enterprise Storage
Ubuntu
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
Anolis OS
openEuler
libspreadsheet-parseexcel-perl (Ubuntu package)
perl-Spreadsheet-ParseExcel-help
perl-Spreadsheet-ParseExcel
perl-Spreadsheet-ParseExcel-debugsource
perl-Spreadsheet-ParseExcel-debuginfo
dev-perl/Spreadsheet-ParseExcel
libspreadsheet-parseexcel-perl (Debian package)
perl-Spreadsheet-ParseExcel-doc
Tanzu Greenplum
How to mitigate CVE-2023-7101
Install update from vendor's website.
Spreadsheet-ParseExcel - update to 0.66
libspreadsheet-parseexcel-perl (Ubuntu package) - addressed in versions Ubuntu Pro, 0.6500-1ubuntu0.20.04.1, 0.6500-1.1ubuntu0.1
perl-Spreadsheet-ParseExcel-help - update to 0.65-2
perl-Spreadsheet-ParseExcel - update to 0.65-2
perl-Spreadsheet-ParseExcel-debugsource - update to 0.65-2
perl-Spreadsheet-ParseExcel-debuginfo - update to 0.65-2
perl-Spreadsheet-ParseExcel - update to 0.65-150000.3.3.1
dev-perl/Spreadsheet-ParseExcel - update to 0.660.0
perl-Spreadsheet-ParseExcel - addressed in versions 0.5900-5.3, 0.6500-28
libspreadsheet-parseexcel-perl (Debian package) - addressed in versions 0.6500-1.1+deb11u1, 0.6500-4~deb12u1
perl-Spreadsheet-ParseExcel-doc - update to 0.6600-1
perl-Spreadsheet-ParseExcel - update to 0.6600-1
perl-Spreadsheet-ParseExcel - addressed in versions 0.6600-1.el7, 0.6600-1.el8, 0.6600-1.el9, 0.6600-1.fc38, 0.6600-1.fc39
Tanzu Greenplum - update to 7.4.0
libspreadsheet-parseexcel-perl (Ubuntu package) - addressed in versions Ubuntu Pro, 0.6500-1ubuntu0.20.04.1, 0.6500-1.1ubuntu0.1
perl-Spreadsheet-ParseExcel-help - update to 0.65-2
perl-Spreadsheet-ParseExcel - update to 0.65-2
perl-Spreadsheet-ParseExcel-debugsource - update to 0.65-2
perl-Spreadsheet-ParseExcel-debuginfo - update to 0.65-2
perl-Spreadsheet-ParseExcel - update to 0.65-150000.3.3.1
dev-perl/Spreadsheet-ParseExcel - update to 0.660.0
perl-Spreadsheet-ParseExcel - addressed in versions 0.5900-5.3, 0.6500-28
libspreadsheet-parseexcel-perl (Debian package) - addressed in versions 0.6500-1.1+deb11u1, 0.6500-4~deb12u1
perl-Spreadsheet-ParseExcel-doc - update to 0.6600-1
perl-Spreadsheet-ParseExcel - update to 0.6600-1
perl-Spreadsheet-ParseExcel - addressed in versions 0.6600-1.el7, 0.6600-1.el8, 0.6600-1.el9, 0.6600-1.fc38, 0.6600-1.fc39
Tanzu Greenplum - update to 7.4.0
Links to Public Exploits and PoC-codes
External References
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-2023-0019.md
- https://https://www.cve.org/CVERecord?id=CVE-2023-7101
- https://https://metacpan.org/dist/Spreadsheet-ParseExcel
- https://https://github.com/haile01/perl_spreadsheet_excel_rce_poc
- https://github.com/jmcnamara/spreadsheet-parseexcel/blob/c7298592e102a375d43150cd002feed806557c15/lib/Spreadsheet/ParseExcel/Utility.pm#L171
- https://metacpan.org/dist/Spreadsheet-ParseExcel/changes
Related Security Bulletins
- Arbitrary code execution in Spreadsheet-ParseExcel
- Fedora 38 update for perl-Spreadsheet-ParseExcel
- Fedora 39 update for perl-Spreadsheet-ParseExcel
- Fedora EPEL 8 update for perl-Spreadsheet-ParseExcel
- Fedora EPEL 9 update for perl-Spreadsheet-ParseExcel
- Fedora EPEL 7 update for perl-Spreadsheet-ParseExcel
- SUSE update for perl-Spreadsheet-ParseExcel
- Amazon Linux AMI update for perl-Spreadsheet-ParseExcel
- Ubuntu update for libspreadsheet-parseexcel-perl
- Debian update for libspreadsheet-parseexcel-perl
- Amazon Linux AMI update for perl-Spreadsheet-ParseExcel
- VMware Tanzu Greenplum update for third-party components
- Gentoo update for Spreadsheet-ParseExcel
- openEuler 24.03 LTS SP1 update for perl-Spreadsheet-ParseExcel
- openEuler 24.03 LTS update for perl-Spreadsheet-ParseExcel
- openEuler 24.03 LTS SP2 update for perl-Spreadsheet-ParseExcel
- Anolis OS update for perl-Spreadsheet-ParseExcel