HTTP: Oracle Document Capture ActiveX Control WriteJPG Buffer Overflow
This signature detects attempts to exploit a known buffer overflow vulnerability in NCSECWLib ActiveX control component included with Oracle Document Capture. It is due to a improper bounds ochecking of arguments within the object's WriteJPG method. Remote attackers can exploit this by enticing target users to visit a malicious Web page. A successful attack can lead to injection and execution of arbitrary code on the target system with the privileges of the logged in user.
Extended Description
Oracle Document Capture is prone to file-overwrite and buffer-overflow vulnerabilities. An attacker can exploit these issues to overwrite arbitrary files, and possibly run arbitrary code. This vulnerability affects the following supported versions: 10.1.3.4, 10.1.3.5
Affected Products
Oracle document_capture
References
BugTraq: 45856
CVE: CVE-2010-3599
URL: http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Oracle
9.4