CVE-2002-0857

Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:database_server:7.3.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:database_server:9.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:database_server:9.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:oracle8i:8.1:*:*:*:*:*:*:*

History

20 Nov 2024, 23:40

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=102933735716634&w=2 - () http://marc.info/?l=bugtraq&m=102933735716634&w=2 -
References () http://otn.oracle.com/deploy/security/pdf/2002alert40rev1.pdf - Patch, Vendor Advisory () http://otn.oracle.com/deploy/security/pdf/2002alert40rev1.pdf - Patch, Vendor Advisory
References () http://securitytracker.com/id?1005037 - () http://securitytracker.com/id?1005037 -
References () http://www.kb.cert.org/vuls/id/301059 - US Government Resource () http://www.kb.cert.org/vuls/id/301059 - US Government Resource
References () http://www.ngssoftware.com/advisories/ora-lsnrfmtstr.txt - () http://www.ngssoftware.com/advisories/ora-lsnrfmtstr.txt -
References () http://www.securityfocus.com/bid/5460 - () http://www.securityfocus.com/bid/5460 -

Information

Published : 2002-09-05 04:00

Updated : 2024-11-20 23:40


NVD link : CVE-2002-0857

Mitre link : CVE-2002-0857

CVE.ORG link : CVE-2002-0857


JSON object : View

Products Affected

oracle

  • oracle8i
  • database_server