Description
HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
Remediation
References
http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150228.html
http://poi.apache.org/changes.html
http://secunia.com/advisories/61953
http://www-01.ibm.com/support/docview.wss?uid=swg21996759
http://www.securityfocus.com/bid/77726
https://access.redhat.com/errata/RHSA-2016:1135
https://issues.apache.org/bugzilla/show_bug.cgi?id=57272
Related Vulnerabilities
CVE-2013-4517 Vulnerability in maven package org.apache.santuario:xmlsec
CVE-2014-0193 Vulnerability in maven package io.netty:netty-codec-http
CVE-2014-3584 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-xml
CVE-2012-2145 Vulnerability in maven package org.apache.qpid:qpid-common
CVE-2014-0110 Vulnerability in maven package org.apache.cxf:cxf-bundle