PT-2009-3593 · Oracle+1 · Oracle Application Server+2
Published
2009-04-15
·
Updated
2014-01-14
·
CVE-2009-1011
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Application Server versions 8.2.2 through 8.3.0
Description
The issue affects confidentiality, integrity, and availability, and is related to HTML. It is reportedly due to multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.
Recommendations
For Oracle Application Server versions 8.2.2 through 8.3.0, consider restricting access to the Outside In Technology component until a fix is available.
As a temporary workaround, avoid using the affected function that parses Microsoft Office files to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office
Oracle Application Server
Outside In Technology