81790 : Apache POI src/org/apache/poi/hwpf/model/UnhandledDataStructure.java UnhandledDataStructure() constructor Length Attribute CDF / CFBF File Handling Remote DoS
Printer |
http://osvdb.org/81790 |
Email This
| Edit Vulnerability
Views This Week
Views All Time
Added to OSVDB
Last Modified
Modified (since 2008)
Percent Complete
3
506
about 1 year ago
5 months ago
5 times
100%
Timeline
Disclosure Date
2012-05-09
Description
Apache POI contains a flaw that may allow a remote denial of service. The issue is triggered when a validation check of the length attribute is not performed in the UnhandledDataStructure() constructor in src/org/apache/poi/hwpf/model/UnhandledDataStructure.java when handling CDF or CFBF files. This will result in a loss of availability for the program.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Denial of Service
Impact:
Loss of Availability
Solution:
Patch / RCS
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Debian has released a patch to address this vulnerability. Check the vendor changelog in the references section.