Return-Path: X-Original-To: apmail-poi-commits-archive@minotaur.apache.org Delivered-To: apmail-poi-commits-archive@minotaur.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id CABF211D19 for ; Wed, 13 Aug 2014 13:10:40 +0000 (UTC) Received: (qmail 69500 invoked by uid 500); 13 Aug 2014 13:10:40 -0000 Delivered-To: apmail-poi-commits-archive@poi.apache.org Received: (qmail 69464 invoked by uid 500); 13 Aug 2014 13:10:40 -0000 Mailing-List: contact commits-help@poi.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@poi.apache.org Delivered-To: mailing list commits@poi.apache.org Received: (qmail 69455 invoked by uid 99); 13 Aug 2014 13:10:40 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 13 Aug 2014 13:10:40 +0000 X-ASF-Spam-Status: No, hits=-2000.0 required=5.0 tests=ALL_TRUSTED X-Spam-Check-By: apache.org Received: from [140.211.11.4] (HELO eris.apache.org) (140.211.11.4) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 13 Aug 2014 13:10:39 +0000 Received: from eris.apache.org (localhost [127.0.0.1]) by eris.apache.org (Postfix) with ESMTP id 2C06C2388831; Wed, 13 Aug 2014 13:10:19 +0000 (UTC) Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: svn commit: r1617724 - /poi/site/src/documentation/content/xdocs/status.xml Date: Wed, 13 Aug 2014 13:10:19 -0000 To: commits@poi.apache.org From: uschindler@apache.org X-Mailer: svnmailer-1.0.9 Message-Id: <20140813131019.2C06C2388831@eris.apache.org> X-Virus-Checked: Checked by ClamAV on apache.org Author: uschindler Date: Wed Aug 13 13:10:18 2014 New Revision: 1617724 URL: http://svn.apache.org/r1617724 Log: Add CVE numbers Modified: poi/site/src/documentation/content/xdocs/status.xml Modified: poi/site/src/documentation/content/xdocs/status.xml URL: http://svn.apache.org/viewvc/poi/site/src/documentation/content/xdocs/status.xml?rev=1617724&r1=1617723&r2=1617724&view=diff ============================================================================== --- poi/site/src/documentation/content/xdocs/status.xml (original) +++ poi/site/src/documentation/content/xdocs/status.xml Wed Aug 13 13:10:18 2014 @@ -42,21 +42,21 @@ --> - + For XSLF Pictures, provide a way to get the URI of externally linked pictures - On supported XML parser versions (Xerces or JVM built-in, XMLBeans 2.6), enforce sensible limits on entity expansion in OOXML files, and ensure that subsequent normal files still pass fine + On supported XML parser versions (Xerces or JVM built-in, XMLBeans 2.6), enforce sensible limits on entity expansion in OOXML files, and ensure that subsequent normal files still pass fine (CVE-2014-3574) Recommended Apache XMLBeans version increased to 2.6.0 (any version from 2.3.0 or later will work though) Provide a helpful exception, XLSBUnsupportedException, if XSSFWorkbook is passed a .xlsb file Switch from dom4j to JAXP - - On supported XML parser versions (Xerces or JVM built-in, XMLBeans 2.6), enforce sensible limits on entity expansion in OOXML files, and ensure that subsequent normal files still pass fine - Tidy up the OPC SAX setup code with a new common Helper, preventing external entity expansion + + On supported XML parser versions (Xerces or JVM built-in, XMLBeans 2.6), enforce sensible limits on entity expansion in OOXML files, and ensure that subsequent normal files still pass fine (CVE-2014-3574) + Tidy up the OPC SAX setup code with a new common Helper, preventing external entity expansion (CVE-2014-3529) - Tidy up the OPC SAX setup code with a new common Helper, preventing external entity expansion + Tidy up the OPC SAX setup code with a new common Helper, preventing external entity expansion (CVE-2014-3529) Correct XWPF createTOC handling of short style names If the start+end row and cell are the same on an AreaPtg, avoid inverting the relative flag HWPF where no parent style CHP exists, use an empty set when processing the style to avoid a NPE --------------------------------------------------------------------- To unsubscribe, e-mail: commits-unsubscribe@poi.apache.org For additional commands, e-mail: commits-help@poi.apache.org