Oracle Network Authentication CVE-2009-1979 Remote Buffer Overflow Vulnerability
BID:36747
Info
Oracle Network Authentication CVE-2009-1979 Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 36747 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-1979 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2009 12:00AM |
| Updated: | Jan 22 2010 09:01AM |
| Credit: | Oracle |
| Vulnerable: |
Oracle Oracle10g Standard Edition 10.1 .5 Oracle Oracle10g Standard Edition 10.2.0.4 Oracle Oracle10g Enterprise Edition 10.1 .5 Oracle Oracle10g Enterprise Edition 10.2.0.4 |
| Not Vulnerable: | |
Discussion
Oracle Network Authentication CVE-2009-1979 Remote Buffer Overflow Vulnerability
Oracle Network Authentication is prone to a remote buffer-overflow vulnerability.
The vulnerability can be exploited over the 'Oracle Net' protocol. An attacker doesn't need specific privileges to exploit this vulnerability.
Oracle Database 10g versions 10.1.0.5 and 10.2.0.4.
Oracle Network Authentication is prone to a remote buffer-overflow vulnerability.
The vulnerability can be exploited over the 'Oracle Net' protocol. An attacker doesn't need specific privileges to exploit this vulnerability.
Oracle Database 10g versions 10.1.0.5 and 10.2.0.4.
Exploit / POC
Oracle Network Authentication CVE-2009-1979 Remote Buffer Overflow Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
Solution / Fix
Oracle Network Authentication CVE-2009-1979 Remote Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for details.
Solution:
Vendor updates are available. Please contact the vendor for details.
References
Oracle Network Authentication CVE-2009-1979 Remote Buffer Overflow Vulnerability
References:
References:
- CVE-2009-1979 (Oracle RDBMS) (Dennis Yurichev
) - Oracle Critical Patch Update Advisory - October 2009 (Oracle)