Oracle Database Server DIRECTORY Buffer Overflow Vulnerability
BID:6850
Info
Oracle Database Server DIRECTORY Buffer Overflow Vulnerability
| Bugtraq ID: | 6850 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2003 12:00AM |
| Updated: | Feb 11 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to David Litchfield of Next Generation Software. |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.2 .0.2 Oracle Oracle9i Standard Edition 9.2 .0.1 Oracle Oracle9i Standard Edition 9.0.1 .3 Oracle Oracle9i Standard Edition 9.0.1 .2 Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 9.0 Oracle Oracle8i Standard Edition 8.1.7 Oracle Oracle8 8.0.6 |
| Not Vulnerable: | |
Exploit / POC
Oracle Database Server DIRECTORY Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Oracle Database Server DIRECTORY Buffer Overflow Vulnerability
Solution:
Oracle has made fixes available. Administrators can download the patches at http://metalink.oracle.com by entering Bug Number 2642117.
The attached Oracle advisory also contains a release schedule for patches across all supported platforms.
Solution:
Oracle has made fixes available. Administrators can download the patches at http://metalink.oracle.com by entering Bug Number 2642117.
The attached Oracle advisory also contains a release schedule for patches across all supported platforms.
References
Oracle Database Server DIRECTORY Buffer Overflow Vulnerability
References:
References:
- Oracle Homepage (Oracle)
- Oracle Security Alert #48 (Oracle)
- Vulnerability Note VU#663786 (CERT/CC)
- Oracle bfilename function buffer overflow vulnerability (#NISR16022003e) ("NGSSoftware Insight Security Research"
)