Description
Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
Remediation
References
http://www.securityfocus.com/bid/102879
https://access.redhat.com/errata/RHSA-2018:1322
https://lists.apache.org/thread.html/453d9af5dbabaccd9afb58d27279a9dbfe8e35f4e5ea1645ddd6960b%40%3Cdev.poi.apache.org%3E
https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Related Vulnerabilities
CVE-2022-25918 Vulnerability in npm package shescape
CVE-2022-39300 Vulnerability in npm package node-saml
CVE-2023-40167 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2016-4978 Vulnerability in maven package org.apache.activemq:artemis-jms-client
CVE-2019-17359 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk15on