Oracle Database 'CTXSYS.DRVDISP' Buffer Overflow Vulnerability
BID:50199
Info
Oracle Database 'CTXSYS.DRVDISP' Buffer Overflow Vulnerability
| Bugtraq ID: | 50199 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-2301 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2011 12:00AM |
| Updated: | Oct 24 2011 07:52PM |
| Credit: | Oracle |
| Vulnerable: |
Oracle Oracle11g Standard Edition 11.1 .7 Oracle Oracle11g Standard Edition 11.1.0.7 R1 Oracle Oracle11g Enterprise Edition 11.1.0.7 R1 Oracle Oracle11g Enterprise Edition 11.1.0.7 Oracle Oracle10g Standard Edition 10.2 .3 Oracle Oracle10g Personal Edition 10.2 .3 R2 Oracle Oracle10g Personal Edition 10.1 .5 r1 Oracle Oracle10g Personal Edition 10.1 .5 Oracle Oracle10g Personal Edition 10.2.0.4 Oracle Oracle10g Enterprise Edition 10.2 .3 Oracle Oracle10g Enterprise Edition 11.1.0.7 |
| Not Vulnerable: | |
Discussion
Oracle Database 'CTXSYS.DRVDISP' Buffer Overflow Vulnerability
Oracle Database is prone to a buffer-overflow vulnerability that exists in Oracle Text.
The vulnerability can be exploited over the 'Oracle Net' protocol. For an exploit to succeed, the attacker must have 'Execute on CTXSYS.DRVDISP' privileges.
Successful exploits will allow attackers to execute arbitrary code in the context of the affected application. This may facilitate a complete system compromise.
This vulnerability affects the following supported versions:
10.1.0.5, 10.2.0.3, 10.2.0.4, 11.1.0.7ww
Oracle Database is prone to a buffer-overflow vulnerability that exists in Oracle Text.
The vulnerability can be exploited over the 'Oracle Net' protocol. For an exploit to succeed, the attacker must have 'Execute on CTXSYS.DRVDISP' privileges.
Successful exploits will allow attackers to execute arbitrary code in the context of the affected application. This may facilitate a complete system compromise.
This vulnerability affects the following supported versions:
10.1.0.5, 10.2.0.3, 10.2.0.4, 11.1.0.7ww
Exploit / POC
Oracle Database 'CTXSYS.DRVDISP' Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Database 'CTXSYS.DRVDISP' Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle Database 'CTXSYS.DRVDISP' Buffer Overflow Vulnerability
References:
References: