Описание
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | poi | Affected | ||
| Red Hat Enterprise Linux 8 | apache-poi | Not affected | ||
| Red Hat JBoss BRMS 5 | poi | Not affected | ||
| Red Hat JBoss BRMS 6 | poi | Affected | ||
| Red Hat JBoss Data Virtualization 6 | poi | Will not fix | ||
| Red Hat JBoss Fuse Service Works 6 | poi | Will not fix | ||
| Red Hat JBoss Portal 6 | poi | Will not fix | ||
| Red Hat JBoss A-MQ 6.3 | poi | Fixed | RHSA-2018:1322 | 03.05.2018 |
| Red Hat JBoss Fuse 6.3 | poi | Fixed | RHSA-2018:1322 | 03.05.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
Apache POI in versions prior to release 3.17 are vulnerable to Denial ...
Уязвимость Java-библиотеки для чтения и записи документов MS Office Apache POI, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.3 Medium
CVSS3