PT-2005-1741 · Oracle · Oracle Database Server

Cesar Cerrudo

·

Publicado

2005-03-07

·

Atualizado

2016-10-18

·

CVE-2005-0701

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Database Server versions 8i and 9i
Description A directory traversal issue allows remote attackers to read or rename arbitrary files via modified dot dot backslash sequences to UTL FILE functions, such as UTL FILE.FOPEN or UTL FILE.frename.
Recommendations For Oracle Database Server version 8i, update to a version that includes the fix for this issue. For Oracle Database Server version 9i, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the UTL FILE functions, such as UTL FILE.FOPEN and UTL FILE.frename, until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0701

Produtos afetados

Oracle Database Server