Vulnerability Name:

CCN-77267

Published:2012-07-17
Updated:2012-07-17
Summary:Oracle Outside In Technology related to Outside In Filters is vulnerable to a denial of service, caused by a heap-based buffer overflow in the FPX graphic import filter (ibfpx2.flt). By persuading a victim to open a specially-crafted FPX image file, a remote attacker could exploit this vulnerability to overflow a buffer and cause a denial of service.

Note: This vulnerability also affects other products containing a bundled version of the Oracle Outside In Technology libraries.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: SA50019
Microsoft Exchange Server Oracle Outside In Technology Multiple Vulnerabilities

Source: CCN
Type: SA50049
Microsoft SharePoint and FAST Search Server Oracle Outside In Technology Multiple Vulnerabilities

Source: CCN
Type: Microsoft Security Advisory (2737111)
Vulnerabilities in Microsoft Exchange and FAST Search Server 2010 for SharePoint Parsing Could Allow Remote Code Execution

Source: CCN
Type: US-CERT VU#118913
Oracle Outside In contains multiple exploitable vulnerabilities

Source: CCN
Type: Oracle Critical Patch Update Advisory - July 2012
Oracle Critical Patch Update Advisory - July 2012

Source: CCN
Type: PRL-2012-26
Oracle Outside-In FPX File Parsing Heap Overflow

Source: XF
Type: UNKNOWN
outsideintechnology-fpx-dos(77267)

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:oracle:fusion_middleware:8.3.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:fusion_middleware:8.3.7.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:microsoft:sharepoint_server:2010:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:2007:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:2010:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:2010:sp2:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    oracle fusion middleware 8.3.5.0
    oracle fusion middleware 8.3.7.0
    microsoft sharepoint server 2010 sp1
    microsoft exchange server 2007 sp3
    microsoft exchange server 2010 sp1
    microsoft exchange server 2010 sp2