PT-2011-2643 · Oracle · Oracle Outside In Technology+1
Will Dormann
·
Published
2011-04-20
·
Updated
2016-05-25
·
CVE-2011-0794
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Fusion Middleware version 8.3.5.0
Oracle Outside In Technology versions 8.3.5.x through 8.3.5.5684
Description
The issue affects confidentiality, integrity, and availability. It is related to the File ID SDK. The vulnerability can be exploited when using the CAB file identification functionality to parse certain file formats, including OneNote (.onepkg) files.
Recommendations
For Oracle Fusion Middleware version 8.3.5.0, update to a version that is not affected by this issue.
For Oracle Outside In Technology versions 8.3.5.x through 8.3.5.5684, consider restricting access to the
sccut.dll or libsc ut.so libraries until a patch is available.
As a temporary workaround, avoid using the CAB file identification functionality to parse OneNote (.onepkg) files and other formats until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Fusion Middleware
Oracle Outside In Technology