PT-2003-1364 · Oracle · Oracle Database
Mark Litchfield
·
Publicado
2003-02-21
·
Atualizado
2016-10-18
·
CVE-2003-0096
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Database versions 8.0.6, 8.1.7, 9i Release 1, and 9i Release 2
Description
The issue is related to multiple buffer overflows that allow remote attackers to execute arbitrary code. This can be achieved through a long conversion string argument to the
TO TIMESTAMP TZ function, a long time zone argument to the TZ OFFSET function, or a long DIRECTORY parameter to the BFILENAME function.Recommendations
For Oracle Database version 8.0.6, update to a version that includes the fix for this issue.
For Oracle Database version 8.1.7, update to a version that includes the fix for this issue.
For Oracle Database version 9i Release 1, update to a version that includes the fix for this issue.
For Oracle Database version 9i Release 2, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the
TO TIMESTAMP TZ, TZ OFFSET, and BFILENAME functions until a patch is available.Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Oracle Database