PT-2004-2280 · Oracle · Oracle 10G
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Oracle 10g
Description:
A buffer overflow issue exists in the extproc component, allowing remote attackers to execute arbitrary code. This is achieved by manipulating environment variables in the library name, which are expanded after the length check is performed.
Recommendations:
For Oracle 10g, consider restricting access to the extproc component until a fix is available. As a temporary workaround, avoid using environment variables in library names to minimize the risk of exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Oracle 10G