Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9527

Опубликовано: 21 дек. 2014
Источник: redhat
CVSS2: 4.3

Описание

HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.

A denial of service flaw was found in the way the HSLFSlideShow class implementation in Apache POI handled certain PPT files. A remote attacker could submit a specially crafted PPT file that would cause Apache POI to hang indefinitely.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6apache-poiAffected
Red Hat Enterprise Virtualization 3jasperreports-server-proUnder investigation
Red Hat JBoss BRMS 5apache-poiWill not fix
Red Hat JBoss BRMS 6apache-poiAffected
Red Hat JBoss Fuse Service Works 6apache-poiAffected
Red Hat JBoss Portal 6apache-poiWill not fix
Red Hat Satellite 5.6jakarta-poiUnder investigation
Red Hat JBoss Data Virtualization 6.2apache-poiFixedRHSA-2016:113526.05.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1181223apache-poi: denial of service in HSLFSlideShow via corrupted PPT file

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.

nvd
около 11 лет назад

HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.

debian
около 11 лет назад

HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cau ...

github
больше 3 лет назад

Loop with Unreachable Exit Condition in Apache POI

4.3 Medium

CVSS2