PT-2006-1335 · Oracle · Oracle Database Server

Alexander Kornbrust

+8

·

Published

2006-01-18

·

Updated

2017-07-20

·

CVE-2006-0260

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Database server versions 9.2.0.7 and 10.1.0.5
Description The issue involves multiple unspecified vulnerabilities in various components of the Oracle Database server, including the Data Pump, Oracle Text, Streams Apply, Streams Capture, and Streams Subcomponent. One of the vulnerabilities, DB05, is claimed by a reliable independent researcher to involve SQL injection in several functions within the DBMS METADATA UTIL, DBMS METADATA INT, and DBMS METADATA packages. These functions include LONG2VARCHAR, LONG2VCMAX, LONG2VCNT, LONG2CLOB, MAKE FILTER, FETCH VIEWS ERROR, FETCH FILTERS, FETCH VIEWS, SET FILTER COMMON, DO FILTER SCRIPT, SET TABLE FILTERS, MAKE FILTER TEXT, and GET PREPOST TABLE ACT.
Recommendations For Oracle Database server version 9.2.0.7, consider disabling the affected functions in the DBMS METADATA UTIL, DBMS METADATA INT, and DBMS METADATA packages as a temporary workaround until a patch is available. For Oracle Database server version 10.1.0.5, consider disabling the affected functions in the DBMS METADATA UTIL, DBMS METADATA INT, and DBMS METADATA packages as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0260

Affected Products

Oracle Database Server