5
CVSSv2

CVE-2014-9527

Published: 06/01/2015 Updated: 11/02/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

HSLFSlideShow in Apache POI prior to 3.11 allows remote malicious users to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 20

apache poi

Vendor Advisories

Debian Bug report logs - #775171 libapache-poi-java: CVE-2014-9527 Package: libapache-poi-java; Maintainer for libapache-poi-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Source for libapache-poi-java is src:libapache-poi-java (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inu ...
A denial of service flaw was found in the way the HSLFSlideShow class implementation in Apache POI handled certain PPT files A remote attacker could submit a specially crafted PPT file that would cause Apache POI to hang indefinitely ...