PT-2012-2405 · Apache · Apache Poi
Jan Lieskovsky
·
Publicado
2012-08-07
·
Atualizado
2022-05-04
·
CVE-2012-0213
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache POI versions 3.8 and earlier
Description
The issue allows remote attackers to cause a denial of service, potentially leading to an OutOfMemoryError exception and JVM destabilization, by exploiting a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document. This is due to a problem in the UnhandledDataStructure function.
Recommendations
For Apache POI versions 3.8 and earlier, consider updating to a version later than 3.8 to resolve the issue. As a temporary workaround, restrict the processing of CDF or CFBF documents from untrusted sources to minimize the risk of exploitation.
Correção
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Poi