Oracle Outside In '.cdr' File Remote Code Execution Vulnerability
29 Jul. 2011
Summary
This allows context-dependent attackers to affect confidentiality, integrity, and availability via unknown vectors related to Outside In Filters. NOTE: the previous information was obtained from the July 2011 CPU. Oracle has not commented on claims from a reliable third party that this is a stack-based buffer overflow in the imcdr2.flt library for the CorelDRAW parser.
Oracle Outside In is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to open a malicious '.cdr' file.
Successful exploits will result in the execution of arbitrary code in the context of the application using the affected library. Failed exploit attempts may result in a denial-of-service condition.
Vendor Status:
Oracle as issued an update for this vulnerablity