Asymmetric denial of service In org.apache.poi:poi
Description
Denial of Service in Apache POI The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 3.10-beta1 | ||
maven | 3.10-beta1 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6.