Oracle Application Server 10g emagent.exe Stack Overflow Vulnerability
BID:15146
Info
Oracle Application Server 10g emagent.exe Stack Overflow Vulnerability
| Bugtraq ID: | 15146 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2005 12:00AM |
| Updated: | Oct 20 2005 12:00AM |
| Credit: | Discovery credited to SPI Labs <[email protected]>. |
| Vulnerable: |
Oracle Application Server 10g 10.1.2 |
| Not Vulnerable: | |
Discussion
Oracle Application Server 10g emagent.exe Stack Overflow Vulnerability
Oracle Application Server 10g is prone to a buffer overflow. Successful exploitation could allow arbitrary code execution with SYSTEM privileges.
This vulnerability was originally described in Oracle October Security Update Multiple Vulnerabilities (BID 15134). Due to the availability of additional information, it has been assigned its own record.
Oracle Application Server 10g is prone to a buffer overflow. Successful exploitation could allow arbitrary code execution with SYSTEM privileges.
This vulnerability was originally described in Oracle October Security Update Multiple Vulnerabilities (BID 15134). Due to the availability of additional information, it has been assigned its own record.
Exploit / POC
Oracle Application Server 10g emagent.exe Stack Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Oracle Application Server 10g emagent.exe Stack Overflow Vulnerability
Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - October 2005) to address these issues. Information regarding obtaining and applying appropriate patches can be found in the referenced Oracle Critical Patch Update.
Pre-installation notes for Oracle Application Server can be found at the
following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333959.1
Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - October 2005) to address these issues. Information regarding obtaining and applying appropriate patches can be found in the referenced Oracle Critical Patch Update.
Pre-installation notes for Oracle Application Server can be found at the
following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333959.1
References
Oracle Application Server 10g emagent.exe Stack Overflow Vulnerability
References:
References:
- Critical Patch Update - October 2005 (Oracle)
- Oracle Homepage (Oracle)
- Oracle 10g - emagent.exe Stack-Based Overflow ("SPI Labs"
)