Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:ACTIVEX:ORACLE-DOC-CAP

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Oracle Document Capture ActiveX Control WriteJPG Buffer Overflow

Release Date

2011/02/03

Update Number

1859

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Oracle Document Capture ActiveX Control WriteJPG Buffer Overflow


This signature detects attempts to exploit a known buffer overflow vulnerability in NCSECWLib ActiveX control component included with Oracle Document Capture. It is due to a improper bounds ochecking of arguments within the object's WriteJPG method. Remote attackers can exploit this by enticing target users to visit a malicious Web page. A successful attack can lead to injection and execution of arbitrary code on the target system with the privileges of the logged in user.

Extended Description

Oracle Document Capture is prone to file-overwrite and buffer-overflow vulnerabilities. An attacker can exploit these issues to overwrite arbitrary files, and possibly run arbitrary code. This vulnerability affects the following supported versions: 10.1.3.4, 10.1.3.5

Affected Products

  • Oracle Document Capture 10.1.3.4
  • Oracle Document Capture 10.1.3.5.0

References

  • BugTraq: 45856
  • CVE: CVE-2010-3599
  • URL: http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out