PT-2007-1742 · Oracle · Oracle Database

Published

2007-01-17

·

Updated

2018-10-16

·

CVE-2007-0270

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Database versions 9.2.0.7 and 10.1.0.4
Description The issue is related to a buffer overflow in SYS.DBMS DRS, which can be exploited by remote authenticated users. This can lead to a denial of service (crash) or the execution of arbitrary code via the GET PROPERTY function in SYS.DBMS DRS.
Recommendations For Oracle Database version 9.2.0.7, consider disabling the GET PROPERTY function in SYS.DBMS DRS as a temporary workaround until a patch is available. For Oracle Database version 10.1.0.4, consider disabling the GET PROPERTY function in SYS.DBMS DRS as a temporary workaround until a patch is available.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0270

Affected Products

Oracle Database