CVE-2012-0213
libjakarta-poi-java - unbounded memory allocation
EPSS 13.1%
Description
The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
How to fix CVE-2012-0213
To remediate CVE-2012-0213, upgrade the affected package to a fixed version below.
- Debian/libjakarta-poi-java—upgrade to 3.6+dfsg-1+squeeze1 or later
- Maven/org.apache.poi:poi—upgrade to 3.10-beta1 or later
- —upgrade to 3.10-beta1 or later
Is CVE-2012-0213 being exploited?
Moderate — EPSS is 13.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 3.6+dfsg-1+squeeze1
- from 0, < 3.10-beta1
- from 0, < 3.10-beta1