PRL-2012-30

#####################################################################################

Application:   Oracle Outside-In JPG File Parsing Denial of Service

Version:   the vulnerabilities are reported in versions 8.3.5 and 8.3.7.

Exploitation:   Remote code execution

Secunia Number:   SA50993

{PRL}:   2012-30

Author:   Francis Provencher (Protek Research Lab’s)

Website:   http://www.protekresearchlab.com/

Twitter:   @ProtekResearch

#####################################################################################

1) Introduction
2) Timeline
3) Technical details
4) PoC

#####################################################################################

===============
1) Introduction
===============

Oracle Outside In Technology provides software developers with a comprehensive solution to access,

transform, and control the contents of over 500 unstructured file formats. From the latest office suites,

such as Microsoft Office 2007, to specialty formats and legacy files, Outside In Technology provides software

developers with the tools to transform unstructured files into controllable information.

#####################################################################################

============
2) Timeline
============
2012-07-09 – Vulnerability reported to secunia
2012-10-17 – Coordinated public release of advisory

#####################################################################################

=================
3) Technical details
=================

An indexing error in the JPG graphic import filter (ibjpg2.flt) when processing the

number of components within a progressive DCT-based image (SOF2) can be exploited

to reference an invalid memory handle causing a crash via a specially crafted quantization

table selector value.

#####################################################################################

=============
4) The Code
=============

Here

###############################################################################