Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

Denial of Service in Apache POI

GHSA-jqx5-h2hw-5q4f · CVE-2012-0213

Published · Modified

Description

The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.

Ready to move

Start Securing

Free, no credit card | First findings in minutes