#943565 libapache-poi-java: CVE-2019-12415

Package:
src:libapache-poi-java
Source:
libapache-poi-java
Submitter:
Salvatore Bonaccorso
Date:
2026-09-21 11:43:07 UTC
Severity:
important
Tags:
#943565#5
Date:
2019-10-26 15:03:20 UTC
From:
To:
Hi,

The following vulnerability was published for libapache-poi-java.

CVE-2019-12415[0]:
| In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to
| convert user-provided Microsoft Excel documents, a specially crafted
| document can allow an attacker to read files from the local filesystem
| or from internal network resources via XML External Entity (XXE)
| Processing.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-12415
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12415

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#943565#8
Date:
2026-09-21 10:32:02 UTC
From:
To:
Hello,

Bug #943565 in libapache-poi-java reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/java-team/libapache-poi-java/-/commit/87db63c8caf1d6d96a1532dbf501195fd7d3c14b

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/943565

#943565#15
Date:
2026-09-21 11:40:45 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libapache-poi-java, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 943565@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Emmanuel Bourg <ebourg@apache.org> (supplier of updated libapache-poi-java package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 21 Sep 2026 11:56:32 +0200
Source: libapache-poi-java
Architecture: source
Version: 4.1.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Emmanuel Bourg <ebourg@apache.org>
Closes: 943565 1012016
Changes:
 libapache-poi-java (4.1.1-1) unstable; urgency=medium
 .
   * New upstream release
     - Fixes CVE-2019-12415 (Closes: #943565)
     - Refreshed the patches
     - New build dependency on libmockito-java
     - New dependency on libbatik-java for the SVG image renderer
     - New build dependency on libguava-java
   * Adapted the build to the XMLBeans 4 metadata layout, the compiled
     schemas were dropped from poi-ooxml-schemas.jar and no OOXML document
     could be opened (Closes: #1012016)
   * Added commons-io to the test classpath, commons-compress requires it
   * Removed the libapache-poi-java-doc package
   * Repaired debian/orig-tar.sh (ECMA and ETSI URLs, SVN tag naming)
   * Standards-Version updated to 4.7.4
Checksums-Sha1:
 1f5312b51f497ae9ce6bd9cbc8ba5c0fb83b8762 2542 libapache-poi-java_4.1.1-1.dsc
 c060feab6a55b193b0f1fedf54192b603a8cda3d 79453564 libapache-poi-java_4.1.1.orig.tar.xz
 8e74d306a284931bd5a058f1676b1d80c3e081dd 17648 libapache-poi-java_4.1.1-1.debian.tar.xz
 ef46587114c713998b34cea4389c3bcc5e04203a 17887 libapache-poi-java_4.1.1-1_source.buildinfo
Checksums-Sha256:
 2867578083525b9a046519f537a869f77a331b19de275ce4251f8597428704d2 2542 libapache-poi-java_4.1.1-1.dsc
 d9799ada064a68fc8ab46e55534ff9a6b09279a4b6212bc75da57c5875b14262 79453564 libapache-poi-java_4.1.1.orig.tar.xz
 a82d518cc150772f430eeb3e030d6ed76072916fde516e0c901a6f4c235f75ec 17648 libapache-poi-java_4.1.1-1.debian.tar.xz
 0a9bb400d8753ae0554aa25ed005b5fdcd4ed5d5ce32cc2c37266a95d83e9962 17887 libapache-poi-java_4.1.1-1_source.buildinfo
Files:
 f5234e851337a4bd1687c4ee26d58923 2542 java optional libapache-poi-java_4.1.1-1.dsc
 993a31f89f806d7be4b50bf38fc60424 79453564 java optional libapache-poi-java_4.1.1.orig.tar.xz
 1791eca4b0ec505e96bc22342e2cd0c0 17648 java optional libapache-poi-java_4.1.1-1.debian.tar.xz
 118a820f4c47c4d9df3bd440ca3a5958 17887 java optional libapache-poi-java_4.1.1-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJGBAEBCgAwFiEEuM5N4hCA3PkD4WxA9RPEGeS50KwFAmqxB4ASHGVib3VyZ0Bh
cGFjaGUub3JnAAoJEPUTxBnkudCslkQQAMaOetlIDGL2ukiKFmTUej2Z3BRasGYp
sQhrFxqg3IfBOr6WeshpXLdIjL2Ua5yj2RSRvX/9DKDWRkvjiWs4kE3rj4FyMXfw
zVDcHCppkDtBLVNOkZ1ADia8NekR7VA+yBQof3i7Wq70C/QO+3kJvpJ/md/qYBuO
3NfmGqcR/KfkwaygKokZFxe1uYAU9V6o+4rdCKoO6+tPu5qRX8jVzxQTX1q5hkFO
Bk2wSYCSc8aFhzbH2Gzq3vT1OdiHRNaMiD3/DaWyZhxRfFj/KxwD2ZOox4GNEhu/
01BcFHAna4Dp+K0TUDcMVM3BSn9RDkw8RL8q9Hp/3lz+pNsZK7gsE4BN2NQm05S0
Hmzj5LViYtjghz1QznbuH+zGqV1yQC2f9uClKPrz2QqFaMp4fQn35+uQ1JgABLT4
Y67CZF+ENFwSMBwOCbXh5RYeVCeR2l5WsoSVljgSe1lUX0JYe1sLU3SbquB1XR3m
16zY34HVqF0S7ctLwFogJTUD21DqpOH5eyWr2nuwU3fW4Fp9R3T37J6v3L5pTt4E
Nq/rD7k2mv7LcitzzYoAV3fzI2rP/pvUDiEP2Y3Oeq9YZ+/P6aKI+K5Ute39/WNw
i9XCySCUwf7gfdCt3sjtGK58ewrcnC/L/0oQH+y8/MeoOlk9LKwTGQZzRrg4WYpe
uP6Xn0ZxaKJV
=uAu9
-----END PGP SIGNATURE-----