Overview
A remotely exploitable buffer overflow vulnerability exists in Oracle9i Database.
Description
Impact
A remote attacker may be able to execute arbitrary code with the privileges of the vulnerable process. This process typically runs as "Oracle" on Linux and UNIX hosts and as "Local System" on Windows systems. |
Solution
Oracle has published Oracle Security Alert #48 regarding this issue. Patches do not yet exist for all platforms. Please refer to Oracle Security Alert #48 for a detailed patch matrix. |
Workarounds
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was discovered by David Litchfield (david@ngssoftware.com) of Next Generation Security Software Ltd. The CERT/CC thanks both Next Generation Security Software Ltd and Oracle for providing information upon which this document is based.
This document was written by Ian A Finlay.
Other Information
CVE IDs: | None |
Severity Metric: | 27.00 |
Date Public: | 2003-02-11 |
Date First Published: | 2003-02-18 |
Date Last Updated: | 2003-02-19 15:41 UTC |
Document Revision: | 8 |