PT-2004-2280 · Oracle · Oracle 10G

David Litchfield

·

Published

2004-08-04

·

Updated

2024-02-02

·

CVE-2004-1363

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Oracle 10g
Description: A buffer overflow issue exists in the extproc component, allowing remote attackers to execute arbitrary code. This is achieved by manipulating environment variables in the library name, which are expanded after the length check is performed.
Recommendations: For Oracle 10g, consider restricting access to the extproc component until a fix is available. As a temporary workaround, avoid using environment variables in library names to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2004-1363

Affected Products

Oracle 10G