DataCollector Spreadsheet::ParseExcel Vulnerability CVE-2023-7101

book

Article ID: 100067965

calendar_today

Updated On:

Description

Error Message

Security scanners report the Perl module as vulnerable. 

Cause

From CVE.org 

CVE Record | CVE

"Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic."

Resolution

Update the SORT DataCollector to version 7.0.20240620 or later using either of the following two methods: 

 

1.) Update the version while executing the DataCollector

The data collector version on local machine is: 6.6.20230419
An updated Data Collector version, 7.0.20240620, is available on Veritas SORT Update Server.
The data collector can be updated either manually, or automatically via the Internet. Updating the data collector gives you the latest bug fixes.

Do you want to automatically update the SORT data collector to the latest version via the Internet? [y,n,q] (y)

 

Note: The host must have access to the internet to perform the update. 

 

2.) If the host does not have internet access, manually download the latest DataCollector version from the SORT website.  

https://docs.infoscale.com

 

Issue/Introduction

Security scanner located vulnerability in Perl module Spreadsheet::ParseExcel

Additional Information

JIRA: [SORT-5399]