Infinite loop in Apache POI - CVE-2017-12626

 

Infinite loop in Apache POI - CVE-2017-12626

Published: May 18, 2018


Vulnerability identifier: #VU12842
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12626
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to infinite loops while parsing specially crafted WMF, EMF, MSG and macros and out of Memory exceptions while parsing specially crafted DOC, PPT and XLS. A remote attacker can cause the service to crash.

Affected software

Apache POI
IBM OmniFind Text Search Server for DB2 for i
IBM Intelligent Operations Center
Oracle Communications Unified Inventory Management
Oracle Communications Diameter Signaling Router (DSR)
Oracle Enterprise Data Quality
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite - Manage Component
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Oracle Utilities Network Management System
Dell Support Assist Enterprise
Oracle Retail Xstore Point of Service
Oracle FLEXCUBE Private Banking
Oracle Application Testing Suite
IBM Engineering Systems Design Rhapsody
Oracle Endeca Information Discovery Studio
Oracle Endeca Information Discovery Integrator
Oracle Insurance Policy Administration
Oracle Enterprise Repository
JBoss Enterprise Application Platform
Primavera Gateway
PeopleSoft Enterprise PeopleTools
Oracle Agile PLM Framework
Oracle Retail Sales Audit
Instantis EnterpriseTrack
Primavera Unifier
Fedora
apache-poi

How to mitigate CVE-2017-12626

Update to version 3.17.

Dell Support Assist Enterprise - update to 4.00.06.00
IBM Intelligent Operations Center - update to 5.2.4
apache-poi - update to 3.17-1.fc28
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.26, 8.7.20, 9.0.13
IBM Engineering Systems Design Rhapsody - update to 9.0.1.0.5
IBM Business Automation Workflow - addressed in versions 21.0.3 IF028, 23.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6

External References

Related Security Bulletins