CVE-2012-0213
published 2012-08-07CVE-2012-0213: The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
7.50%
93.8th percentile
The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | poi | <= 3.8 | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
| apache | poi | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Denial of Service in Apache POI
osv·2022-05-04
CVE-2012-0213 [MEDIUM] Denial of Service in Apache POI
Denial of Service in Apache POI
The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
GHSA
Denial of Service in Apache POI
ghsa·2022-05-04
CVE-2012-0213 [MEDIUM] CWE-400 Denial of Service in Apache POI
Denial of Service in Apache POI
The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
Red Hat
jakarta: JVM destabilization due to memory exhaustion when processing CDF/CFBF files
vendor_redhat·2012-05-09·CVSS 5.0
CVE-2012-0213 [MEDIUM] jakarta: JVM destabilization due to memory exhaustion when processing CDF/CFBF files
jakarta: JVM destabilization due to memory exhaustion when processing CDF/CFBF files
The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
Package: Portal (Red Hat JBoss Portal 5) - Affected
Package: unspecified (Red Hat JBoss SOA Platform 4.3) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0213 apache-poi, jakarta: JVM destabilization due to memory exhaustion when processing CDF/CFBF files [fedora-all]
bugzilla·2012-05-11·CVSS 5.0
CVE-2012-0213 [MEDIUM] CVE-2012-0213 apache-poi, jakarta: JVM destabilization due to memory exhaustion when processing CDF/CFBF files [fedora-all]
CVE-2012-0213 apache-poi, jakarta: JVM destabilization due to memory exhaustion when processing CDF/CFBF files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://adm
Bugzilla
CVE-2012-0213 apache-poi, jakarta: JVM destabilization due to memory exhaustion when processing CDF/CFBF files
bugzilla·2012-03-01·CVSS 5.0
CVE-2012-0213 [MEDIUM] CVE-2012-0213 apache-poi, jakarta: JVM destabilization due to memory exhaustion when processing CDF/CFBF files
CVE-2012-0213 apache-poi, jakarta: JVM destabilization due to memory exhaustion when processing CDF/CFBF files
A flaw was found in the way Apache POI, the Java API for Microsoft Office file formats, handles memory when processing certain Channel Definition Format (CDF) / Compound File Binary Format (CFBF) documents. Apache POI allocates arrays with arbitrary sizes specified in the document. A remote attacker could exploit this flaw by providing a specially-crafted CDF / CFBF file to an application using Apache POI, leading to an to OutOfMemoryError exception in the current thread, or potentially destabilization of the whole Java Virtual Machine instance.
Discussion:
This issue affects the versions of the apache-poi package, as shipped with Fedora release of 15 and 16.
---
Created atta
http://lists.fedoraproject.org/pipermail/package-announce/2012-August/084609.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1232.htmlhttp://secunia.com/advisories/49040http://secunia.com/advisories/50549http://www-01.ibm.com/support/docview.wss?uid=swg21996759http://www.debian.org/security/2012/dsa-2468http://www.mandriva.com/security/advisories?name=MDVSA-2013:094http://www.securityfocus.com/bid/53487https://bugzilla.redhat.com/show_bug.cgi?id=799078https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0044http://lists.fedoraproject.org/pipermail/package-announce/2012-August/084609.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1232.htmlhttp://secunia.com/advisories/49040http://secunia.com/advisories/50549http://www-01.ibm.com/support/docview.wss?uid=swg21996759http://www.debian.org/security/2012/dsa-2468http://www.mandriva.com/security/advisories?name=MDVSA-2013:094http://www.securityfocus.com/bid/53487https://bugzilla.redhat.com/show_bug.cgi?id=799078https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0044
2012-08-07
Published