Skip to content

Denial of Service in Apache POI

Moderate severity GitHub Reviewed Published May 4, 2022 to the GitHub Advisory Database • Updated Mar 5, 2024

Package

maven org.apache.poi:poi (Maven)

Affected versions

< 3.10-beta1

Patched versions

3.10-beta1
maven org.apache.poi:poi-scratchpad (Maven)
< 3.10-beta1
3.10-beta1

Description

The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.

References

Published by the National Vulnerability Database Aug 7, 2012
Published to the GitHub Advisory Database May 4, 2022
Reviewed Jul 13, 2022
Last updated Mar 5, 2024

Severity

Moderate

EPSS score

1.069%
(84th percentile)

Weaknesses

CVE ID

CVE-2012-0213

GHSA ID

GHSA-jqx5-h2hw-5q4f

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.