Junglewise Threat Intelligence

CVE-2017-3270: Oracle Outside In Technology denial of service in Outside In Filters

CVE-2017-3270 · Severity: high · CVSS 7.5 · Published 2017-01-27

Technologies: Oracle Outside In Technology. Vendors: Oracle.

Executive brief

Oracle Outside In Technology is a set of software development kits used by applications to extract, normalize, and convert content from over 600 different file formats. A vulnerability in the 'Outside In Filters' component allows an unauthenticated attacker to remotely crash the service or cause it to hang. This results in a complete denial-of-service, preventing the host application from processing files and potentially disrupting business operations that rely on document conversion or data extraction.

Technical details

A vulnerability exists in the Outside In Filters subcomponent of Oracle Outside In Technology (part of Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. While the specific vulnerability class (e.g., buffer overflow, infinite loop) is not explicitly detailed in the advisory, the impact is a complete loss of availability (Denial of Service) through a repeatable crash or hang. The vulnerability's severity is dependent on how the host application implements the SDK; it assumes the application passes network-received data directly to the Outside In code. Affected versions include 8.5.2 and 8.5.3. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Outside In Technology 8.5.2, 8.5.3

Timeline

  • 2017-01-27: advisory: Initial disclosure by Oracle
  • 2017-01-27: patched: Fix released in January 2017 Critical Patch Update

References

Related threats