Oracle Outside In Technology Microsoft CAB File Parsing Remote Code Execution Vulnerability
BID:47437
Info
Oracle Outside In Technology Microsoft CAB File Parsing Remote Code Execution Vulnerability
| Bugtraq ID: | 47437 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-0808 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 19 2011 12:00AM |
| Updated: | Mar 19 2015 09:41AM |
| Credit: | Will Dormann of the CERT/CC |
| Vulnerable: |
Symantec Enterprise Vault 9.0.2 Symantec Enterprise Vault 9.0.1 Symantec Enterprise Vault 9.0 Symantec Enterprise Vault 8.0 SP5 Symantec Enterprise Vault 8.0 SP4 Symantec Enterprise Vault 8.0 Symantec Enterprise Vault 7.5 Symantec Enterprise Vault 10.0 Oracle Outside In 8.3.5.0 Oracle Outside In 8.3.2.0 Novell Groupwise 32-bit Client 0 Novell Groupwise 7.0 Novell Groupwise 6.5.7 Novell Groupwise 6.5.6 Novell Groupwise 6.5.4 Novell Groupwise 6.5.3 Novell Groupwise 6.5.2 Novell Groupwise 6.5 SP6 Update 1 Novell Groupwise 6.5 SP6 Novell Groupwise 6.5 Post SP6 Novell Groupwise 6.5 SP5 Novell Groupwise 6.5 SP4 Novell Groupwise 6.5 SP3 Novell Groupwise 6.5 SP2 Novell Groupwise 6.5 SP1 Novell Groupwise 6.5 Novell Groupwise 6.0 SP4 Novell Groupwise 6.0 SP3 Novell Groupwise 6.0 SP2 Novell Groupwise 6.0 SP1 Novell Groupwise 6.0 Novell Groupwise 5.5 Novell Groupwise 5.2 Novell Groupwise 8.02 HP2 Novell Groupwise 8.02 HP1 Novell Groupwise 8.02 Novell Groupwise 8.01x Novell Groupwise 8.0 SP2 Novell Groupwise 8.0 SP1 Novell Groupwise 8.0 HP2 Novell Groupwise 8.0 HP1 Novell Groupwise 8.0 Novell Groupwise 7.04 Novell Groupwise 7.03x Novell Groupwise 7.03HP1a Novell Groupwise 7.03 HP4 Novell Groupwise 7.03 HP3 Novell Groupwise 7.03 HP2 Novell Groupwise 7.03 Novell Groupwise 7.02x Novell Groupwise 7.02 Novell Groupwise 7.01 Novell Groupwise 7.0.0 SP3 Novell Groupwise 7.0.0 SP2 Novell Groupwise 7.0.0 SP1 Novell Groupwise 7.0 SP4 Novell Groupwise 6.5 SP6 Update 3 Novell Groupwise 5.57e Kamel Software Fastlook 2009 0 IBM WEB Interface for Content Management 1.0.4 IBM WEB Interface for Content Management 1.0.3 IBM WEB Interface for Content Management 1.0.2 IBM WEB Interface for Content Management 1.0.1 IBM Production Imaging Edition 5.0 IBM InfoSphere Classification Module 8.7 IBM FileNet Integrated Document Management Desktop 4.0.3 IBM FileNet Integrated Document Management Desktop 4.0.2 IBM FileNet Content Manager 5.1 IBM FileNet Content Manager 5.0 IBM FileNet Capture 5.2.1 IBM FileNet Capture 5.2 IBM eDiscovery Manager 2.2 IBM eDiscovery Analyzer 2.2 IBM Document Manager 8.4.2 IBM Document Manager 2.2 IBM Content Manager Enterprise Edition 8.4.3 IBM Content Integrator 8.5.1 IBM Content Integrator 8.6 IBM Content Collector for Microsoft SharePoint 2.2 IBM Content Collector for Microsoft SharePoint 2.1.1 IBM Content Collector for File Systems 2.2 IBM Content Collector for File Systems 2.1.1 IBM Content Collector for Email 2.2 IBM Content Collector for Email 2.1.1 IBM Content Analytics 2.2 IBM Content Analytics 2.1 IBM CommonStore for Lotus Domino 8.4 IBM CommonStore for Exchange 8.4 IBM Classification Module 8.6 HP Trim 0 Guidance Software EnCase Forensic V4 4.18 a Guidance Software EnCase Forensic 6.14 Guidance Software EnCase Forensic 6.12 Guidance Software EnCase Forensic 5.0 Guidance Software EnCase Enterprise 4.16 Guidance Software EnCase Enterprise 4.0 Guidance Software EnCase 0 Cisco Security Agent 6.0.2.145 Cisco Security Agent 6.0.1.132 Cisco Security Agent 6.0(2.099) Cisco Security Agent 6.0(1.126) Cisco Security Agent 6.0 Avantstar Inc. Quick View Plus 11 ACD Systems Inc ACDSee Canvas 12 build 1389 ACD Systems Inc ACDSee Canvas 12 AccessData Group FTK 3.2 |
| Not Vulnerable: |
Novell Groupwise 8.0 HP3 Cisco Security Agent 6.0.2.151 |
Discussion
Oracle Outside In Technology Microsoft CAB File Parsing Remote Code Execution Vulnerability
Oracle Outside In Technology is prone to a remote code-execution vulnerability when handling specially crafted Microsoft CAB files.
A remote attacker can exploit this issue to execute arbitrary code in the context of the application using the affected library.
This vulnerability affects the following supported versions:
8.3.2.0, 8.3.5.0
Oracle Outside In Technology is prone to a remote code-execution vulnerability when handling specially crafted Microsoft CAB files.
A remote attacker can exploit this issue to execute arbitrary code in the context of the application using the affected library.
This vulnerability affects the following supported versions:
8.3.2.0, 8.3.5.0
Exploit / POC
Oracle Outside In Technology Microsoft CAB File Parsing Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Outside In Technology Microsoft CAB File Parsing Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Symantec Enterprise Vault 9.0
Symantec Enterprise Vault 10.0
Symantec Enterprise Vault 9.0.2
Solution:
Vendor updates are available. Please contact the vendor for more information.
Symantec Enterprise Vault 9.0
-
Symantec Hotfix for Symantec Enterprise Vault (EV) 9.0.0, Build 1193, Implement 8.3.7 converters patch for se
http://www.symantec.com/business/support/index?page=content&id=TECH167 912
Symantec Enterprise Vault 10.0
-
Symantec Hotfix for Symantec Enterprise Vault (EV) 10.0.0, Build 1316, Implement 8.3.7 converters patch for s
http://www.symantec.com/business/support/index?page=content&id=TECH168 021
Symantec Enterprise Vault 9.0.2
-
Symantec Hotfix for Symantec Enterprise Vault (EV) 9.0.2, Build 1061, Implement 8.3.7 converters patch for se
http://www.symantec.com/business/support/index?page=content&id=TECH167 767
References
Oracle Outside In Technology Microsoft CAB File Parsing Remote Code Execution Vulnerability
References:
References:
- Security Bulletin: Potential Oracle Outside In Technology Vulnerabilities Expose (IBM)
- Cisco Security Agent Remote Code Execution Vulnerabilities (Cisco)
- Oracle Critical Patch Update Advisory - April 2011 (Oracle)
- Security Bulletin: Potential Oracle Outside In Technology Vulnerabilities Expose (IBM)
- Security Vulnerability in Oracle 'Outside-In' (Lotus 123 & Microsoft CAB) viewer (Novell)
- SYM11-011 Symantec Enterprise Vault Update for Oracle Outside In Module (Symantec)
- Vulnerability Note VU#520721 Oracle Outside In contains exploitable vulnerabilit (US-CERT)