ZDI-CAN-29543: ZDI-26-636: Oracle Outside In Technology PostScript File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60412.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-26-636 - Compensating control
Apply the mitigation described in ZDI-26-636 for Oracle Outside In Technology (PostScript file parsing heap-based buffer overflow leading to remote code execution), since user interaction is required (victim must visit a malicious page or open a malicious file).
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must cause the target to visit a malicious page or open a malicious file. Successful exploitation can allow the attacker to execute arbitrary code on the affected installation.
Is this exploitable without user interaction?
No. Exploitation requires user interaction by the target, specifically visiting a malicious page or opening a malicious file.