PT-2006-2852 · Oracle · Oracle Database Server

Alexander Kornbrust

·

Published

2006-04-20

·

Updated

2018-10-18

·

CVE-2006-1868

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Database Server version 10.1.0.4
Description The issue is related to a buffer overflow in the Advanced Replication component. This allows database users to execute arbitrary code via the VERIFY LOG procedure of the DBMS SNAPSHOT UTL package.
Recommendations For Oracle Database Server version 10.1.0.4, consider disabling the VERIFY LOG procedure of the DBMS SNAPSHOT UTL package as a temporary workaround until a patch is available. Restrict access to the DBMS SNAPSHOT UTL package to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-1868

Affected Products

Oracle Database Server