CVE-2017-5644
published 2017-03-24CVE-2017-5644: Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an…
PriorityP425medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
4.59%
90.6th percentile
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | poi | <= 3.14 | — |
| apache_software_foundation | apache_poi | — | — |
| debian | libapache-poi-java | < libapache-poi-java 3.17-1 (bookworm) | libapache-poi-java 3.17-1 (bookworm) |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Restriction of Recursive Entity References in DTDs in Apache POI
osv·2022-05-13
CVE-2017-5644 [MEDIUM] Improper Restriction of Recursive Entity References in DTDs in Apache POI
Improper Restriction of Recursive Entity References in DTDs in Apache POI
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
GHSA
Improper Restriction of Recursive Entity References in DTDs in Apache POI
ghsa·2022-05-13
CVE-2017-5644 [MEDIUM] CWE-776 Improper Restriction of Recursive Entity References in DTDs in Apache POI
Improper Restriction of Recursive Entity References in DTDs in Apache POI
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
OSV
CVE-2017-5644: Apache POI in versions prior to release 3
osv·2017-03-24·CVSS 5.5
CVE-2017-5644 [MEDIUM] CVE-2017-5644: Apache POI in versions prior to release 3
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Debian
CVE-2017-5644: libapache-poi-java - Apache POI in versions prior to release 3.15 allows remote attackers to cause a ...
vendor_debian·2017·CVSS 5.5
CVE-2017-5644 [MEDIUM] CVE-2017-5644: libapache-poi-java - Apache POI in versions prior to release 3.15 allows remote attackers to cause a ...
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Scope: local
bookworm: resolved (fixed in 3.17-1)
bullseye: resolved (fixed in 3.17-1)
forky: resolved (fixed in 3.17-1)
sid: resolved (fixed in 3.17-1)
trixie: resolved (fixed in 3.17-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5644 apache-poi: XML entity expansion via specially crafted OOXML file [fedora-all]
bugzilla·2017-03-21·CVSS 5.5
CVE-2017-5644 [MEDIUM] CVE-2017-5644 apache-poi: XML entity expansion via specially crafted OOXML file [fedora-all]
CVE-2017-5644 apache-poi: XML entity expansion via specially crafted OOXML file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2017-5644 apache-poi: XML entity expansion via specially crafted OOXML file
bugzilla·2017-03-21·CVSS 5.5
CVE-2017-5644 [MEDIUM] CVE-2017-5644 apache-poi: XML entity expansion via specially crafted OOXML file
CVE-2017-5644 apache-poi: XML entity expansion via specially crafted OOXML file
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
References:
http://www.openwall.com/lists/oss-security/2017/03/20/9
Discussion:
Created apache-poi tracking bugs for this issue:
Affects: fedora-all [bug 1434523]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
arXiv
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
arxiv_fulltext·2018-07-12
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
## Abstract
The use of open-source software (OSS) is ever-increasing, and so is the number of open-source vulnerabilities being discovered and publicly disclosed. The gains obtained from the reuse of community-developed libraries may be offset by the cost of timely detecting, assessing, and mitigating their vulnerabilities.
In this paper we present a novel method to detect, assess and mitigate OSS vulnerabilities that improves on state-of-the-art approaches, which commonly depend on metadata to identify vulnerable OSS dependencies. Our solution instead is code-centric and combines static and dynamic analysis to determine the reachability of the vulnerable portion of libraries used (directly or transitively) by an application. Taking this usage into account, our approach then supports dev
http://poi.apache.org/#20+March+2017+-+CVE-2017-5644+-+Possible+DOS+%28Denial+of+Service%29+in+Apache+POI+versions+prior+to+3.15http://www.securityfocus.com/bid/96983https://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://poi.apache.org/#20+March+2017+-+CVE-2017-5644+-+Possible+DOS+%28Denial+of+Service%29+in+Apache+POI+versions+prior+to+3.15http://www.securityfocus.com/bid/96983https://www.oracle.com/security-alerts/cpuoct2020.html
2017-03-24
Published