PT-2004-2676 · Oracle · Oracle
Published
2004-08-31
·
Updated
2017-07-11
·
CVE-2004-1774
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle versions prior to 10.1.0.2 Patch 2
Description
A buffer overflow issue exists in the SDO CODE SIZE procedure of the MD2 package (MDSYS.MD2.SDO CODE SIZE) that allows local users to execute arbitrary code via a long
LAYER parameter.Recommendations
For versions prior to 10.1.0.2 Patch 2, apply Patch 2 to resolve the issue. As a temporary workaround, consider restricting access to the SDO CODE SIZE procedure to minimize the risk of exploitation. Avoid using long values for the
LAYER parameter in the affected procedure until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle