Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:40
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=102933735716634&w=2 - | |
References | () http://otn.oracle.com/deploy/security/pdf/2002alert40rev1.pdf - Patch, Vendor Advisory | |
References | () http://securitytracker.com/id?1005037 - | |
References | () http://www.kb.cert.org/vuls/id/301059 - US Government Resource | |
References | () http://www.ngssoftware.com/advisories/ora-lsnrfmtstr.txt - | |
References | () http://www.securityfocus.com/bid/5460 - |
Information
Published : 2002-09-05 04:00
Updated : 2024-11-20 23:40
NVD link : CVE-2002-0857
Mitre link : CVE-2002-0857
CVE.ORG link : CVE-2002-0857
JSON object : View
Products Affected
oracle
- oracle8i
- database_server
CWE