Oracle Outside In JPEG 2000 COD and COC Parameter Heap Buffer Overflow (CVE-2011-4516)
| Check Point Reference: | CPAI-2012-229 | |
| Date Published: | ||
| Severity: | ||
| Source: | Oracle Advisory cpujan2012-366304 | |
| Industry Reference(s): | CVE-2011-4516 |
|
| Protection Provided by: |
Security Gateway
|
|
|
Who is Vulnerable? Oracle Outside In Technology 8.3.5.0 Oracle Outside In Technology 8.3.7.0 Michael Adams JasPer 1.701 Michael Adams JasPer 1.900 Michael Adams JasPer 1.900.1 |
||
| Vulnerability Description A heap buffer overflow vulnerability exists in Oracle Outside In, a set of libraries used to decode many file formats. Successful exploitation can result in arbitrary code execution in the context of the affected application. |
||
|
Vulnerability Details A vulnerability exists in Oracle Outside In when processing invalid coding style default (COD) marker segments or invalid coding style component (COC) marker segments from JP2 files. This vulnerability can be exploited by causing an application that uses the vulnerable library to handle a malformed JPEG 2000 file. |
Protection Overview
This protection will detect and block malicious JPEG 2000 files.
To configure the defense, select your product from the list below and follow the related protection steps.