All errata/sisyphus/ALT-PU-2016-3318-1
ALT-PU-2016-3318-1

Package update apache-poi in branch sisyphus

Version3.12-alt1_2jpp8
Published2016-02-05
Max severityMEDIUM
Severity:

Closed issues (8)

CVE-2014-3529
MEDIUM4.3

The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Published: 2014-09-04Modified: 2025-04-12
CVSS 2.0MEDIUM 4.3
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:N/A:N
CVE-2014-3574
MEDIUM4.3

Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

Published: 2014-09-04Modified: 2025-04-12
CVSS 2.0MEDIUM 4.3
CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:N/A:P