CVE Database
/

CVE-2012-0213

Back to search

CVE-2012-0213

Published: Aug 7, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.

VendorProductVersions

n/a

n/a

affected
n/a

References

49040
third-party-advisory
x_refsource_SECUNIA
DSA-2468
vendor-advisory
x_refsource_DEBIAN
50549
third-party-advisory
x_refsource_SECUNIA
FEDORA-2012-10835
vendor-advisory
x_refsource_FEDORA
53487
vdb-entry
x_refsource_BID
RHSA-2012:1232
vendor-advisory
x_refsource_REDHAT
MDVSA-2013:094
vendor-advisory
x_refsource_MANDRIVA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now