Executive brief
Oracle Outside In Technology is a suite of software tools used by other applications, such as Microsoft Exchange, to extract and convert content from various file formats. A vulnerability in how these tools process PDF files allows an attacker to send a specially crafted document that causes the system to crash or stop responding. This can lead to a complete denial of service for critical business functions like email attachment scanning.
Technical details
A read access violation exists in the 'vspdf.dll' library of Oracle Outside In Technology when processing PDF files. The vulnerability is located in the code responsible for handling the '/Matrix' entry within a '/CalRGB' entry. The software incorrectly assumes that the '/Matrix' key value contains nine elements; by providing fewer than nine elements in a crafted PDF, an attacker triggers an invalid read. This results in a process crash or hang, leading to a denial of service. This component is notably used by Microsoft Exchange Server for attachment scanning.
Affected products
- Oracle Outside In Technology 8.5.2, 8.5.3
Timeline
- 2016-10-03: other: Vulnerability discovered by Tenable
- 2016-10-17: other: Reported to Oracle
- 2017-01-17: patched: Oracle releases January 2017 Critical Patch Update (CPU)
- 2017-01-27: disclosed: NVD publication date