PT-2007-1746 · Oracle · Oracle Database

Published

2007-01-17

·

Updated

2018-10-16

·

CVE-2007-0274

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Database versions 9.2.0.7 and 10.1.0.5
Description The issue involves multiple unspecified vulnerabilities related to (1) Export and sys.dbms logrep util, and (2) Oracle Streams and sys.dbms capture adm internal privileges. Researcher claims suggest that one of the vulnerabilities is a buffer overflow in the GET OBJECT NAME procedure in the DBMS LOGREP UTIL package, and another involves buffer overflows in the CREATE CAPTURE, ALTER CAPTURE, and ABORT TABLE INSTANTIATION procedures in SYS.DBMS CAPTURE ADM INTERNAL.
Recommendations For Oracle Database version 9.2.0.7, consider disabling the GET OBJECT NAME procedure in the DBMS LOGREP UTIL package and restricting access to the CREATE CAPTURE, ALTER CAPTURE, and ABORT TABLE INSTANTIATION procedures in SYS.DBMS CAPTURE ADM INTERNAL until a patch is available. For Oracle Database version 10.1.0.5, consider disabling the GET OBJECT NAME procedure in the DBMS LOGREP UTIL package and restricting access to the CREATE CAPTURE, ALTER CAPTURE, and ABORT TABLE INSTANTIATION procedures in SYS.DBMS CAPTURE ADM INTERNAL until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0274

Affected Products

Oracle Database