Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3574

Опубликовано: 18 авг. 2014
Источник: redhat
CVSS2: 5

Описание

Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

It was found that Apache POI would expand an unlimited number of entities in OOXML documents. A remote attacker able to supply OOXML documents that are parsed by Apache POI could use this flaw to trigger a denial of service attack via excessive CPU and memory consumption.

Отчет

Red Hat Product Security has determined that CVE-2014-3574 is not exploitable by default in JBoss Portal Platform as provided by Red Hat. This flaw would only be exploitable if the Apache POI library provided by JBoss Portal Platform were used by a custom application to process user-supplied XML documents.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6apache-poiAffected
Red Hat Enterprise Virtualization 3jasperreports-server-proAffected
Red Hat JBoss BRMS 5apache-poiWill not fix
Red Hat JBoss BRMS 6apache-poiAffected
Red Hat JBoss Portal 5apache-poiWill not fix
Red Hat JBoss SOA Platform 4apache-poiWill not fix
Red Hat Satellite 5apache-poiWill not fix
Red Hat JBoss BPMS 6.0FixedRHSA-2014:139913.10.2014
Red Hat JBoss BRMS 6.0FixedRHSA-2014:140013.10.2014
Red Hat JBoss Data Virtualization 6.0apache-poiFixedRHSA-2014:139813.10.2014

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1138140apache-poi: entity expansion (billion laughs) flaw

5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

nvd
почти 12 лет назад

Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

debian
почти 12 лет назад

Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote at ...

github
около 4 лет назад

Improper Input Validation in Apache POI

5 Medium

CVSS2