PT-2003-1441 · Oracle · Oracle Database Server
David Litchfield
·
Published
2003-04-30
·
Updated
2017-07-11
·
CVE-2003-0222
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Oracle Database Server 9i release 2 and earlier
Description:
A stack-based buffer overflow issue exists, allowing attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long
USING parameter.Recommendations:
For Oracle Database Server 9i release 2 and earlier, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Database Server