CVE-2024-22368

The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation does not have appropriate constraints on merged cells.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tozt:spreadsheet\:\:parsexlsx:*:*:*:*:*:perl:*:*

History

21 Nov 2024, 08:56

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/01/10/2 - Exploit, Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2024/01/10/2 - Exploit, Mailing List, Third Party Advisory
References () https://github.com/haile01/perl_spreadsheet_excel_rce_poc/blob/main/parse_xlsx_bomb.md - Exploit, Mitigation, Third Party Advisory () https://github.com/haile01/perl_spreadsheet_excel_rce_poc/blob/main/parse_xlsx_bomb.md - Exploit, Mitigation, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2024/01/msg00018.html - () https://lists.debian.org/debian-lts-announce/2024/01/msg00018.html -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6R7NYWVVZYDZIQC5YEXNHZM6VEE26SJV/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6R7NYWVVZYDZIQC5YEXNHZM6VEE26SJV/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNJVC4C5C5V44DNOZ5BHVU53CDXPB2OJ/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNJVC4C5C5V44DNOZ5BHVU53CDXPB2OJ/ -
References () https://metacpan.org/dist/Spreadsheet-ParseXLSX/changes - Release Notes () https://metacpan.org/dist/Spreadsheet-ParseXLSX/changes - Release Notes
References () https://security.metacpan.org/2024/02/10/vulnerable-spreadsheet-parsing-modules.html - () https://security.metacpan.org/2024/02/10/vulnerable-spreadsheet-parsing-modules.html -

05 May 2024, 15:15

Type Values Removed Values Added
References
  • () https://security.metacpan.org/2024/02/10/vulnerable-spreadsheet-parsing-modules.html -

27 Feb 2024, 04:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6R7NYWVVZYDZIQC5YEXNHZM6VEE26SJV/ -

27 Feb 2024, 02:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNJVC4C5C5V44DNOZ5BHVU53CDXPB2OJ/ -

27 Jan 2024, 22:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/01/msg00018.html -
References () http://www.openwall.com/lists/oss-security/2024/01/10/2 - () http://www.openwall.com/lists/oss-security/2024/01/10/2 - Exploit, Mailing List, Third Party Advisory
References () https://github.com/haile01/perl_spreadsheet_excel_rce_poc/blob/main/parse_xlsx_bomb.md - () https://github.com/haile01/perl_spreadsheet_excel_rce_poc/blob/main/parse_xlsx_bomb.md - Exploit, Mitigation, Third Party Advisory
References () https://metacpan.org/dist/Spreadsheet-ParseXLSX/changes - () https://metacpan.org/dist/Spreadsheet-ParseXLSX/changes - Release Notes
First Time Tozt spreadsheet\
Tozt
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:tozt:spreadsheet\:\:parsexlsx:*:*:*:*:*:perl:*:*

10 Jan 2024, 15:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/01/10/2 -

09 Jan 2024, 14:01

Type Values Removed Values Added
Summary
  • (es) El paquete Spreadsheet::ParseXLSX anterior a 0.28 para Perl puede encontrar una condición de falta de memoria durante el análisis de un documento XLSX manipulado. Esto ocurre porque la implementación de memoize no tiene restricciones apropiadas en las celdas fusionadas.

09 Jan 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-09 09:15

Updated : 2024-11-21 08:56


NVD link : CVE-2024-22368

Mitre link : CVE-2024-22368

CVE.ORG link : CVE-2024-22368


JSON object : View

Products Affected

tozt

  • spreadsheet\