PT-2007-1742 · Oracle · Oracle Database

Publicado

2007-01-17

·

Atualizado

2018-10-16

·

CVE-2007-0270

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Database versions 9.2.0.7 and 10.1.0.4
Description The issue is related to a buffer overflow in SYS.DBMS DRS, which can be exploited by remote authenticated users. This can lead to a denial of service (crash) or the execution of arbitrary code via the GET PROPERTY function in SYS.DBMS DRS.
Recommendations For Oracle Database version 9.2.0.7, consider disabling the GET PROPERTY function in SYS.DBMS DRS as a temporary workaround until a patch is available. For Oracle Database version 10.1.0.4, consider disabling the GET PROPERTY function in SYS.DBMS DRS as a temporary workaround until a patch is available.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-0270

Produtos afetados

Oracle Database