PT-2001-2126 · Oracle · Oracle Internet Directory Server
Published
2001-07-17
·
Updated
2017-12-19
·
CVE-2001-0974
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Internet Directory Server (LDAP) versions 2.1.1.x through 3.0.1
Description
The issue allows remote attackers to execute arbitrary code due to format string vulnerabilities in the LDAP server, as demonstrated by the PROTOS LDAPv3 test suite.
Recommendations
For Oracle Internet Directory Server (LDAP) versions 2.1.1.x through 3.0.1, update to a version that contains a fix for this issue to prevent remote code execution.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Internet Directory Server