Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12626

Опубликовано: 29 янв. 2018
Источник: debian
EPSS Средний

Описание

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libapache-poi-javafixed3.17-1package
libapache-poi-javano-dsastretchpackage
libapache-poi-javano-dsajessiepackage
libapache-poi-javano-dsawheezypackage

Примечания

  • https://bz.apache.org/bugzilla/show_bug.cgi?id=61338

  • https://bz.apache.org/bugzilla/show_bug.cgi?id=61294

  • https://bz.apache.org/bugzilla/show_bug.cgi?id=52372

  • https://bz.apache.org/bugzilla/show_bug.cgi?id=61295

EPSS

Процентиль: 95%
0.10142
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).

CVSS3: 5.3
redhat
больше 8 лет назад

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).

CVSS3: 7.5
nvd
больше 8 лет назад

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).

CVSS3: 7.5
github
больше 5 лет назад

Denial of Service in Apache POI

CVSS3: 7.5
fstec
больше 8 лет назад

Уязвимость Java-библиотеки для чтения и записи документов MS Office Apache POI, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 95%
0.10142
Средний