PT-2005-1741 · Oracle · Oracle Database Server
Cesar Cerrudo
·
Publicado
2005-03-07
·
Atualizado
2016-10-18
·
CVE-2005-0701
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server versions 8i and 9i
Description
A directory traversal issue allows remote attackers to read or rename arbitrary files via modified dot dot backslash sequences to UTL FILE functions, such as
UTL FILE.FOPEN or UTL FILE.frename.Recommendations
For Oracle Database Server version 8i, update to a version that includes the fix for this issue.
For Oracle Database Server version 9i, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the UTL FILE functions, such as
UTL FILE.FOPEN and UTL FILE.frename, until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle Database Server