PT-2012-2405 · Apache · Apache Poi

Jan Lieskovsky

·

Published

2012-08-07

·

Updated

2022-05-04

·

CVE-2012-0213

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache POI versions 3.8 and earlier
Description The issue allows remote attackers to cause a denial of service, potentially leading to an OutOfMemoryError exception and JVM destabilization, by exploiting a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document. This is due to a problem in the UnhandledDataStructure function.
Recommendations For Apache POI versions 3.8 and earlier, consider updating to a version later than 3.8 to resolve the issue. As a temporary workaround, restrict the processing of CDF or CFBF documents from untrusted sources to minimize the risk of exploitation.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-0213
DSA-2468-1
GHSA-JQX5-H2HW-5Q4F

Affected Products

Apache Poi