This allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a JPEG2000 file.
Vulnerable Systems:
*Oracle Outside In 8.3.7
*Oracle Outside In 8.3.5.0
Oracle Outside In is prone to remote heap-based buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage these issues to execute arbitrary code in the context of the application that uses the affected library. Failed attacks will cause denial-of-service conditions.
Vendor Status:
Orcale had since issued an update for this vulnerability.
Disclosure Timeline:
2012-January-23 Rev 3. Updated JD Edwards information for One World Tools SP24
2012-January-18 Rev 2. Updated credit information
2012-January-17 Rev 1. Initial Release