Test data ahihi.xlsx is blocked by sophos malware scanner #15
Replies: 3 comments
-
Are you saying that it gets blocked because of this file? Interesting ... |
Beta Was this translation helpful? Give feedback.
-
Apologies for the delay. I just heard back from Sophos with an explanation of the malware threat: "Thank you for your patience. The submitted file is part of ParseExcel security vulnerability and detection is valid. "The vulnerability is CVE-2023-7101, and it's caused by passing unvalidated input from a file into a string-type “eval”. This can lead to threat actors using the vulnerability to deploy and run malware, including ransomware. "If you have any further queries, we would be happy to assist you and will get back to you within one business day after your response." |
Beta Was this translation helpful? Give feedback.
-
Hm that vulnerability is about Spreadsheet::ParseExcel and not Spreadsheet::ParseXLSX. |
Beta Was this translation helpful? Give feedback.
-
Hi.
Spreadsheet-ParseXLSX-0.35-1/t/data/ahihi.xlsx keeps getting blocked by malware scanner, so I have to use force install to bypass the make tests. I don't see where it's documented what the test t/ahihi.t is for, so I'm not sure if a clean xlsx could be used instead?
What was detected: Exp/237101-A
Beta Was this translation helpful? Give feedback.
All reactions