Updated apache-poi packages fix CVE-2014-9527
Publication date: 26 Feb 2015Modification date: 26 Feb 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-9527
Description
Updated apache-poi packages fixes security vulnerability:
A denial of service flaw was found in the way the HSLFSlideShow class
implementation in Apache POI handled certain PPT files. A remote attacker
could submit a specially crafted PPT file that would cause Apache POI to hang
indefinitely (CVE-2014-9527).
References
SRPMS
4/core
- apache-poi-3.10.1-1.1.mga4