Apache POI Denial of Service Vulnerability (CVE-2014-3574)
Released on: 2014-09-03
Updated on:
Affected Systems:
Apache Group POI 3.11.x
Apache Group POI 3.10.x
Description:
Bugtraq id: 69648
CVE (CAN) ID: CVE-2014-3574
Apache POI is an open-source cross-platform Java API written in Java. It can read and write Microsoft Office files.
Apache POI versions earlier than 3.10.1 and earlier than 3.11-beta2 have the XML Entity Extension Vulnerability in OpenXML parser implementation. Remote attackers can construct OOXML files, this vulnerability can cause denial of service (crashes after CPU usage ).
<* Source: Stefan Kopf
Link: http://secunia.com/advisories/60419
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://poi.apache.org/changes.html
Http://www.apache.org/dist/poi/release/RELEASE-NOTES.txt
Https://lucene.apache.org/solr/solrnews.html#18-august-2014-recommendation-to-update-apache-poi-in-apache-solr-480-481-and-490-installations
POI details: click here
POI: click here
This article permanently updates the link address: