Oracle 9i Application Server DAV_PUBLIC Format String Vulnerability
BID:6846
Info
Oracle 9i Application Server DAV_PUBLIC Format String Vulnerability
| Bugtraq ID: | 6846 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0842 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | The discovery of this vulnerability has been credited to David Litchfield of Next Generation Software. |
| Vulnerable: |
Oracle Oracle9i Application Server 9.0.2 |
| Not Vulnerable: |
Oracle Oracle9i Application Server 9.0.3 |
Solution / Fix
Oracle 9i Application Server DAV_PUBLIC Format String Vulnerability
Solution:
Caldera released an advisory containing fixes for this issue, however, the fixes still included the vulnerable mod_dav module. Caldera has since withdrawn the advisory.
This vulnerability is not present in Oracle 9i Application Server 9.0.3. Users are advised to upgrade or to apply the suggested workaround.
Solution:
Caldera released an advisory containing fixes for this issue, however, the fixes still included the vulnerable mod_dav module. Caldera has since withdrawn the advisory.
This vulnerability is not present in Oracle 9i Application Server 9.0.3. Users are advised to upgrade or to apply the suggested workaround.