CVE-2014-3574
Publication date 4 September 2014
Last updated 24 July 2024
Ubuntu priority
Description
Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libapache-poi-java | ||
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |
References
Other references
- https://issues.apache.org/bugzilla/show_bug.cgi?id=54764
- https://lucene.apache.org/solr/solrnews.html#18-august-2014-recommendation-to-update-apache-poi-in-apache-solr-480-481-and-490-installations
- http://www.apache.org/dist/poi/release/RELEASE-NOTES.txt
- http://secunia.com/advisories/60419
- http://poi.apache.org/changes.html
- https://www.cve.org/CVERecord?id=CVE-2014-3574