Posted by ZDI Disclosures on Jan 23
ZDI-12-017 : Oracle Outside In OOXML Relationship Tag Parsing RemoteCode Execution Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-12-017
January 20, 2012
-- CVE ID:
-- CVSS:
9.7, AV:N/AC:L/Au:N/C:C/I:C/A:P
-- Affected Vendors:
Oracle
-- Affected Products:
Oracle Outside In
-- Vulnerability Details:
This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Oracle Outside In....