Executive brief
Oracle Outside In Technology is a suite of software tools used by other applications, such as Microsoft Exchange, to extract and process content from various file formats. A vulnerability in how these tools handle PDF files allows an attacker to send a specially crafted document that causes the system to freeze or crash. This can lead to a complete denial of service, preventing the host application from processing emails or other data.
Technical details
An infinite loop vulnerability exists in the vspdf.dll library within the Outside In Filters subcomponent of Oracle Outside In Technology. The flaw is triggered when the library recursively retrieves indirect objects from a reference object; if an object refers to itself (e.g., within the /Pages key of a PDF Catalog dictionary), the process enters an infinite loop. An unauthenticated attacker can exploit this by providing a malformed PDF file to an application that utilizes the Outside In SDK (such as Microsoft Exchange's scanning process). Successful exploitation results in 100% CPU usage and a hang or crash of the affected process. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Outside In Technology (Outside In Filters) 8.5.2, 8.5.3
Timeline
- 2016-10-03: other: Issue discovered by Tenable
- 2016-10-17: disclosed: Reported to Oracle
- 2017-01-17: patched: Oracle releases January 2017 Critical Patch Update
- 2017-01-27: advisory: NVD advisory published