Oracle Database Server TO_TIMESTAMP_TZ Buffer Overflow Vulnerability
BID:6847
Info
Oracle Database Server TO_TIMESTAMP_TZ Buffer Overflow Vulnerability
| Bugtraq ID: | 6847 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2003 12:00AM |
| Updated: | Feb 11 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Mark Litchfield. |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.2 .0.2 Oracle Oracle9i Standard Edition 9.2 .0.1 Oracle Oracle9i Standard Edition 9.0.2 Oracle Oracle9i Standard Edition 9.0.1 .3 Oracle Oracle9i Standard Edition 9.0.1 .2 Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 9.0 Oracle Oracle8i Standard Edition 8.1.7 .1 Oracle Oracle8i Standard Edition 8.1.7 Oracle Oracle8 8.0.6 |
| Not Vulnerable: | |
Discussion
Oracle Database Server TO_TIMESTAMP_TZ Buffer Overflow Vulnerability
Oracle Database Server is prone to a buffer overflow in the TO_TIMESTAMP_TZ function. Malicious users who can execute this function with malformed parameters or influence a query which causes this function to be executed may exploit this vulnerability. Successful exploitation will enable the attacker to execute malicious instructions in the context of the database server.
Oracle Database Server is prone to a buffer overflow in the TO_TIMESTAMP_TZ function. Malicious users who can execute this function with malformed parameters or influence a query which causes this function to be executed may exploit this vulnerability. Successful exploitation will enable the attacker to execute malicious instructions in the context of the database server.
Solution / Fix
Oracle Database Server TO_TIMESTAMP_TZ Buffer Overflow Vulnerability
Solution:
Oracle has made fixes available. Administrators can download the patches at http://metalink.oracle.com by entering Bug Number 2642439.
The attached Oracle advisory also contains a release schedule for patches across all supported platforms.
Solution:
Oracle has made fixes available. Administrators can download the patches at http://metalink.oracle.com by entering Bug Number 2642439.
The attached Oracle advisory also contains a release schedule for patches across all supported platforms.