PT-2011-2643 · Oracle · Oracle Outside In Technology+1

Will Dormann

·

Published

2011-04-20

·

Updated

2016-05-25

·

CVE-2011-0794

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Fusion Middleware version 8.3.5.0 Oracle Outside In Technology versions 8.3.5.x through 8.3.5.5684
Description The issue affects confidentiality, integrity, and availability. It is related to the File ID SDK. The vulnerability can be exploited when using the CAB file identification functionality to parse certain file formats, including OneNote (.onepkg) files.
Recommendations For Oracle Fusion Middleware version 8.3.5.0, update to a version that is not affected by this issue. For Oracle Outside In Technology versions 8.3.5.x through 8.3.5.5684, consider restricting access to the sccut.dll or libsc ut.so libraries until a patch is available. As a temporary workaround, avoid using the CAB file identification functionality to parse OneNote (.onepkg) files and other formats until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-0794

Affected Products

Oracle Fusion Middleware
Oracle Outside In Technology