Updated apache-poi packages fix CVE-2014-9527
Publication date: 26 Feb 2015Modification date: 26 Feb 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-9527
Description
Updated apache-poi packages fixes security vulnerability: A denial of service flaw was found in the way the HSLFSlideShow class implementation in Apache POI handled certain PPT files. A remote attacker could submit a specially crafted PPT file that would cause Apache POI to hang indefinitely (CVE-2014-9527).
References
SRPMS
4/core
- apache-poi-3.10.1-1.1.mga4