A serious vulnerability in Spreadsheet::ParseExcel has been announced.
“This library is used by the Amavis virus scanner that runs on Barracuda ESG appliances. An attacker can trigger the vulnerability to execute arbitrary code on vulnerable ESG appliances through parameter injection.”
No mention of specific version numbers or of response from the Perl community in any way. What would we expect to happen in a situation like this?
|
---|
Replies are listed 'Best First'. | |
---|---|
Re: Serious vulnerability in Spreadsheet::ParseExcel
by pryrt (Abbot) on Jan 03, 2024 at 19:59 UTC | |
by Tux (Canon) on Jan 04, 2024 at 08:06 UTC | |
by Cody Fendant (Hermit) on Jan 03, 2024 at 20:09 UTC | |
by LanX (Saint) on Jan 04, 2024 at 03:29 UTC |