PT-2012-2405 · Apache · Apache Poi
Jan Lieskovsky
·
Published
2012-08-07
·
Updated
2022-05-04
·
CVE-2012-0213
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache POI versions 3.8 and earlier
Description
The issue allows remote attackers to cause a denial of service, potentially leading to an OutOfMemoryError exception and JVM destabilization, by exploiting a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document. This is due to a problem in the UnhandledDataStructure function.
Recommendations
For Apache POI versions 3.8 and earlier, consider updating to a version later than 3.8 to resolve the issue. As a temporary workaround, restrict the processing of CDF or CFBF documents from untrusted sources to minimize the risk of exploitation.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Poi