CVE-2012-0213
jakarta: JVM destabilization due to memory exhaustion when processing CDF/CFBF files
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.
La función UnhandledDataStructure en hwpf/model/UnhandledDataStructure.java en Apache POI v3.8 y anteriores permite a atacantes remotos earlier provocar una denegación de servicio (excepción OutOfMemoryError y posiblemente desestabilización JVM) mediante un valor de longitud manipulado en un Channel Definition Format (CDF) o en un documento Compound File Binary Format (CFBF).
JBoss Enterprise Portal Platform is the open source implementation of the Java EE suite of services and Portal services running atop JBoss Enterprise Application Platform. It comprises a set of offerings for enterprise customers who are looking for pre-configured profiles of JBoss Enterprise Middleware components that have been tested and certified together to provide an integrated experience. This release of JBoss Enterprise Portal Platform 5.2.2 serves as a replacement for JBoss Enterprise Portal Platform 5.2.1, and includes bug fixes.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-12-14 CVE Reserved
- 2012-05-10 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/50549 | Third Party Advisory | |
http://www-01.ibm.com/support/docview.wss?uid=swg21996759 | X_refsource_confirm | |
http://www.securityfocus.com/bid/53487 | Vdb Entry | |
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0044 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2012-August/084609.html | 2017-02-11 | |
http://rhn.redhat.com/errata/RHSA-2012-1232.html | 2017-02-11 | |
http://secunia.com/advisories/49040 | 2017-02-11 | |
http://www.debian.org/security/2012/dsa-2468 | 2017-02-11 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2013:094 | 2017-02-11 | |
https://bugzilla.redhat.com/show_bug.cgi?id=799078 | 2012-09-05 | |
https://access.redhat.com/security/cve/CVE-2012-0213 | 2012-09-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | <= 3.8 Search vendor "Apache" for product "Poi" and version " <= 3.8" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.1 Search vendor "Apache" for product "Poi" and version "0.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.2 Search vendor "Apache" for product "Poi" and version "0.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.3 Search vendor "Apache" for product "Poi" and version "0.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.4 Search vendor "Apache" for product "Poi" and version "0.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.5 Search vendor "Apache" for product "Poi" and version "0.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.6 Search vendor "Apache" for product "Poi" and version "0.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.7 Search vendor "Apache" for product "Poi" and version "0.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.10.0 Search vendor "Apache" for product "Poi" and version "0.10.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.11.0 Search vendor "Apache" for product "Poi" and version "0.11.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.12.0 Search vendor "Apache" for product "Poi" and version "0.12.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.13.0 Search vendor "Apache" for product "Poi" and version "0.13.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 0.14.0 Search vendor "Apache" for product "Poi" and version "0.14.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.0.0 Search vendor "Apache" for product "Poi" and version "1.0.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.0.1 Search vendor "Apache" for product "Poi" and version "1.0.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.0.2 Search vendor "Apache" for product "Poi" and version "1.0.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.1.0 Search vendor "Apache" for product "Poi" and version "1.1.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.2.0 Search vendor "Apache" for product "Poi" and version "1.2.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.5 Search vendor "Apache" for product "Poi" and version "1.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.5.1 Search vendor "Apache" for product "Poi" and version "1.5.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.7 Search vendor "Apache" for product "Poi" and version "1.7" | dev |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.8 Search vendor "Apache" for product "Poi" and version "1.8" | dev |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 1.10 Search vendor "Apache" for product "Poi" and version "1.10" | dev |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.0 Search vendor "Apache" for product "Poi" and version "2.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.0 Search vendor "Apache" for product "Poi" and version "2.0" | pre1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.0 Search vendor "Apache" for product "Poi" and version "2.0" | pre2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.0 Search vendor "Apache" for product "Poi" and version "2.0" | pre3 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.0 Search vendor "Apache" for product "Poi" and version "2.0" | rc1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.0 Search vendor "Apache" for product "Poi" and version "2.0" | rc2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.5 Search vendor "Apache" for product "Poi" and version "2.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 2.5.1 Search vendor "Apache" for product "Poi" and version "2.5.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0 Search vendor "Apache" for product "Poi" and version "3.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0 Search vendor "Apache" for product "Poi" and version "3.0" | alpha1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0 Search vendor "Apache" for product "Poi" and version "3.0" | alpha2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0 Search vendor "Apache" for product "Poi" and version "3.0" | alpha3 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0.1 Search vendor "Apache" for product "Poi" and version "3.0.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0.2 Search vendor "Apache" for product "Poi" and version "3.0.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0.2 Search vendor "Apache" for product "Poi" and version "3.0.2" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.0.2 Search vendor "Apache" for product "Poi" and version "3.0.2" | beta2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.1 Search vendor "Apache" for product "Poi" and version "3.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.1 Search vendor "Apache" for product "Poi" and version "3.1" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.1 Search vendor "Apache" for product "Poi" and version "3.1" | beta2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.2 Search vendor "Apache" for product "Poi" and version "3.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | beta2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | beta3 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | beta4 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | beta5 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.5 Search vendor "Apache" for product "Poi" and version "3.5" | beta6 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.6 Search vendor "Apache" for product "Poi" and version "3.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.7 Search vendor "Apache" for product "Poi" and version "3.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.7 Search vendor "Apache" for product "Poi" and version "3.7" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.7 Search vendor "Apache" for product "Poi" and version "3.7" | beta2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.7 Search vendor "Apache" for product "Poi" and version "3.7" | beta3 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.8 Search vendor "Apache" for product "Poi" and version "3.8" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.8 Search vendor "Apache" for product "Poi" and version "3.8" | beta2 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.8 Search vendor "Apache" for product "Poi" and version "3.8" | beta3 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.8 Search vendor "Apache" for product "Poi" and version "3.8" | beta4 |
Affected
| ||||||
Apache Search vendor "Apache" | Poi Search vendor "Apache" for product "Poi" | 3.8 Search vendor "Apache" for product "Poi" and version "3.8" | beta5 |
Affected
|