CVE-2014-3529
Publication date 4 September 2014
Last updated 24 July 2024
Ubuntu priority
Description
The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libapache-poi-java | ||
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |
References
Other references
- https://issues.apache.org/bugzilla/show_bug.cgi?id=56164
- https://lucene.apache.org/solr/solrnews.html#18-august-2014-recommendation-to-update-apache-poi-in-apache-solr-480-481-and-490-installations
- http://www.apache.org/dist/poi/release/RELEASE-NOTES.txt
- http://secunia.com/advisories/60419
- http://poi.apache.org/changes.html
- https://www.cve.org/CVERecord?id=CVE-2014-3529