CVE-2014-9527
published 2015-01-06CVE-2014-9527: HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
7.92%
94.1th percentile
HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | poi | <= 3.11 | — |
| debian | libapache-poi-java | < libapache-poi-java 3.10.1-2 (bookworm) | libapache-poi-java 3.10.1-2 (bookworm) |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
apache-poi: denial of service in HSLFSlideShow via corrupted PPT file
vendor_redhat·2014-12-21·CVSS 5.0
CVE-2014-9527 [MEDIUM] CWE-20 apache-poi: denial of service in HSLFSlideShow via corrupted PPT file
apache-poi: denial of service in HSLFSlideShow via corrupted PPT file
HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
A denial of service flaw was found in the way the HSLFSlideShow class implementation in Apache POI handled certain PPT files. A remote attacker could submit a specially crafted PPT file that would cause Apache POI to hang indefinitely.
Package: apache-poi (Red Hat BPM Suite 6) - Affected
Package: jasperreports-server-pro (Red Hat Enterprise Virtualization 3) - Under investigation
Package: apache-poi (Red Hat JBoss BRMS 5) - Will not fix
Package: apache-poi (Red Hat JBoss BRMS 6) - Affected
Package: apache-poi (Red Hat JBoss Fuse Service Works 6) - Affected
Package: apac
Debian
CVE-2014-9527: libapache-poi-java - HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denia...
vendor_debian·2014·CVSS 5.0
CVE-2014-9527 [MEDIUM] CVE-2014-9527: libapache-poi-java - HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denia...
HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
Scope: local
bookworm: resolved (fixed in 3.10.1-2)
bullseye: resolved (fixed in 3.10.1-2)
forky: resolved (fixed in 3.10.1-2)
sid: resolved (fixed in 3.10.1-2)
trixie: resolved (fixed in 3.10.1-2)
GHSA
Loop with Unreachable Exit Condition in Apache POI
ghsa·2022-05-17
CVE-2014-9527 [MEDIUM] CWE-835 Loop with Unreachable Exit Condition in Apache POI
Loop with Unreachable Exit Condition in Apache POI
HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
OSV
Loop with Unreachable Exit Condition in Apache POI
osv·2022-05-17
CVE-2014-9527 [MEDIUM] Loop with Unreachable Exit Condition in Apache POI
Loop with Unreachable Exit Condition in Apache POI
HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
OSV
CVE-2014-9527: HSLFSlideShow in Apache POI before 3
osv·2015-01-06·CVSS 5.0
CVE-2014-9527 [MEDIUM] CVE-2014-9527: HSLFSlideShow in Apache POI before 3
HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150228.htmlhttp://poi.apache.org/changes.htmlhttp://secunia.com/advisories/61953http://www-01.ibm.com/support/docview.wss?uid=swg21996759http://www.securityfocus.com/bid/77726https://access.redhat.com/errata/RHSA-2016:1135https://issues.apache.org/bugzilla/show_bug.cgi?id=57272http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150228.htmlhttp://poi.apache.org/changes.htmlhttp://secunia.com/advisories/61953http://www-01.ibm.com/support/docview.wss?uid=swg21996759http://www.securityfocus.com/bid/77726https://access.redhat.com/errata/RHSA-2016:1135https://issues.apache.org/bugzilla/show_bug.cgi?id=57272
2015-01-06
Published