All errata/sisyphus/ALT-PU-2017-3665-1
ALT-PU-2017-3665-1

Package update apache-poi in branch sisyphus

Version3.14-alt1_4jpp8
Published2017-11-04
Max severityMEDIUM
Severity:

Closed issues (2)

CVE-2016-5000
MEDIUM5.5

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Published: 2016-08-05Modified: 2025-04-12
CVSS 2.0MEDIUM 4.3
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:N/A:N
CVSS 3.xMEDIUM 5.5
CVSS:3.x/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N