Description
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
Remediation
References
http://www.securityfocus.com/bid/102879
https://access.redhat.com/errata/RHSA-2018:1322
https://lists.apache.org/thread.html/453d9af5dbabaccd9afb58d27279a9dbfe8e35f4e5ea1645ddd6960b%40%3Cdev.poi.apache.org%3E
https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Related Vulnerabilities
CVE-2023-34455 Vulnerability in maven package org.xerial.snappy:snappy-java
CVE-2023-26158 Vulnerability in npm package mockjs
CVE-2018-1331 Vulnerability in maven package org.apache.storm:storm-core
CVE-2016-8738 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2019-10372 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-oauth