5

CVE-2012-0213

The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Poi Version <= 3.8
Apache ≫ Poi Version 0.1
Apache ≫ Poi Version 0.2
Apache ≫ Poi Version 0.3
Apache ≫ Poi Version 0.4
Apache ≫ Poi Version 0.5
Apache ≫ Poi Version 0.6
Apache ≫ Poi Version 0.7
Apache ≫ Poi Version 0.10.0
Apache ≫ Poi Version 0.11.0
Apache ≫ Poi Version 0.12.0
Apache ≫ Poi Version 0.13.0
Apache ≫ Poi Version 0.14.0
Apache ≫ Poi Version 1.0.0
Apache ≫ Poi Version 1.0.1
Apache ≫ Poi Version 1.0.2
Apache ≫ Poi Version 1.1.0
Apache ≫ Poi Version 1.2.0
Apache ≫ Poi Version 1.5
Apache ≫ Poi Version 1.5.1
Apache ≫ Poi Version 1.7 Update dev
Apache ≫ Poi Version 1.8 Update dev
Apache ≫ Poi Version 1.10 Update dev
Apache ≫ Poi Version 2.0
Apache ≫ Poi Version 2.0 Update pre1
Apache ≫ Poi Version 2.0 Update pre2
Apache ≫ Poi Version 2.0 Update pre3
Apache ≫ Poi Version 2.0 Update rc1
Apache ≫ Poi Version 2.0 Update rc2
Apache ≫ Poi Version 2.5
Apache ≫ Poi Version 2.5.1
Apache ≫ Poi Version 3.0
Apache ≫ Poi Version 3.0 Update alpha1
Apache ≫ Poi Version 3.0 Update alpha2
Apache ≫ Poi Version 3.0 Update alpha3
Apache ≫ Poi Version 3.0.1
Apache ≫ Poi Version 3.0.2
Apache ≫ Poi Version 3.0.2 Update beta1
Apache ≫ Poi Version 3.0.2 Update beta2
Apache ≫ Poi Version 3.1
Apache ≫ Poi Version 3.1 Update beta1
Apache ≫ Poi Version 3.1 Update beta2
Apache ≫ Poi Version 3.2
Apache ≫ Poi Version 3.5
Apache ≫ Poi Version 3.5 Update beta1
Apache ≫ Poi Version 3.5 Update beta2
Apache ≫ Poi Version 3.5 Update beta3
Apache ≫ Poi Version 3.5 Update beta4
Apache ≫ Poi Version 3.5 Update beta5
Apache ≫ Poi Version 3.5 Update beta6
Apache ≫ Poi Version 3.6
Apache ≫ Poi Version 3.7
Apache ≫ Poi Version 3.7 Update beta1
Apache ≫ Poi Version 3.7 Update beta2
Apache ≫ Poi Version 3.7 Update beta3
Apache ≫ Poi Version 3.8 Update beta1
Apache ≫ Poi Version 3.8 Update beta2
Apache ≫ Poi Version 3.8 Update beta3
Apache ≫ Poi Version 3.8 Update beta4
Apache ≫ Poi Version 3.8 Update beta5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.5% 0.937
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://rhn.redhat.com/errata/RHSA-2012-1232.html
http://secunia.com/advisories/50549
http://lists.fedoraproject.org/pipermail/package-announce/2012-August/084609.html
http://secunia.com/advisories/49040
Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21996759
http://www.debian.org/security/2012/dsa-2468
http://www.mandriva.com/security/advisories?name=MDVSA-2013:094
http://www.securityfocus.com/bid/53487
https://bugzilla.redhat.com/show_bug.cgi?id=799078
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0044