PT-2009-3593 · Oracle+1 · Oracle Application Server+2

Publicado

2009-04-15

·

Atualizado

2014-01-14

·

CVE-2009-1011

CVSS v2.0

4.4

Média

VetorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Application Server versions 8.2.2 through 8.3.0
Description The issue affects confidentiality, integrity, and availability, and is related to HTML. It is reportedly due to multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.
Recommendations For Oracle Application Server versions 8.2.2 through 8.3.0, consider restricting access to the Outside In Technology component until a fix is available. As a temporary workaround, avoid using the affected function that parses Microsoft Office files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-1011

Produtos afetados

Office
Oracle Application Server
Outside In Technology