Vulnerability Description
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Poi | < 3.17 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/102879Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:1322Third Party Advisory
- https://lists.apache.org/thread.html/453d9af5dbabaccd9afb58d27279a9dbfe8e35f4e5e
- https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c24
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- http://www.securityfocus.com/bid/102879Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:1322Third Party Advisory
- https://lists.apache.org/thread.html/453d9af5dbabaccd9afb58d27279a9dbfe8e35f4e5e
- https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c24
FAQ
What is CVE-2017-12626?
CVE-2017-12626 is a vulnerability with a CVSS score of 7.5 (HIGH). Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Mem...
How severe is CVE-2017-12626?
CVE-2017-12626 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-12626?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Poi.