PT-2004-2280 · Oracle · Oracle 10G

·

CVE-2004-1363

·

Publicado

2004-08-04

·

Atualizado

2024-02-02

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Oracle 10g
Description: A buffer overflow issue exists in the extproc component, allowing remote attackers to execute arbitrary code. This is achieved by manipulating environment variables in the library name, which are expanded after the length check is performed.
Recommendations: For Oracle 10g, consider restricting access to the extproc component until a fix is available. As a temporary workaround, avoid using environment variables in library names to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2004-1363

Produtos afetados

Oracle 10G