Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5644

Опубликовано: 24 мар. 2017
Источник: debian
EPSS Низкий

Описание

Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libapache-poi-javafixed3.17-1package
libapache-poi-javano-dsastretchpackage
libapache-poi-javano-dsajessiepackage
libapache-poi-javano-dsawheezypackage

Примечания

  • https://www.openwall.com/lists/oss-security/2017/03/20/9

EPSS

Процентиль: 74%
0.00792
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

CVSS3: 5.5
nvd
почти 9 лет назад

Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

CVSS3: 5.5
github
больше 3 лет назад

Improper Restriction of Recursive Entity References in DTDs in Apache POI

EPSS

Процентиль: 74%
0.00792
Низкий