Advisories ยป MGASA-2015-0087

Updated apache-poi packages fix CVE-2014-9527

Publication date: 26 Feb 2015
Modification date: 26 Feb 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-9527

Description

Updated apache-poi packages fixes security vulnerability:

A denial of service flaw was found in the way the HSLFSlideShow class
implementation in Apache POI handled certain PPT files. A remote attacker
could submit a specially crafted PPT file that would cause Apache POI to hang
indefinitely (CVE-2014-9527).
                

References

SRPMS

4/core