PT-2003-1364 · Oracle · Oracle Database

Mark Litchfield

·

Publicado

2003-02-21

·

Atualizado

2016-10-18

·

CVE-2003-0096

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Database versions 8.0.6, 8.1.7, 9i Release 1, and 9i Release 2
Description The issue is related to multiple buffer overflows that allow remote attackers to execute arbitrary code. This can be achieved through a long conversion string argument to the TO TIMESTAMP TZ function, a long time zone argument to the TZ OFFSET function, or a long DIRECTORY parameter to the BFILENAME function.
Recommendations For Oracle Database version 8.0.6, update to a version that includes the fix for this issue. For Oracle Database version 8.1.7, update to a version that includes the fix for this issue. For Oracle Database version 9i Release 1, update to a version that includes the fix for this issue. For Oracle Database version 9i Release 2, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the TO TIMESTAMP TZ, TZ OFFSET, and BFILENAME functions until a patch is available.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2003-0096

Produtos afetados

Oracle Database