CVE-2006-1866

Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that DB01 is an unknown issue in the DBMS_REPUTIL package, and DB10 is SQL injection in the INSERT_CATALOG, UPDATE_CATALOG, and DELETE_CATALOG functions of the SDO_CATALOG package.
References
Link Resource
http://secunia.com/advisories/19712 Patch Vendor Advisory
http://secunia.com/advisories/19859 Vendor Advisory
http://securitytracker.com/id?1015961 Patch
http://www.kb.cert.org/vuls/id/139049 US Government Resource
http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html
http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html
http://www.securityfocus.com/archive/1/432267/100/0/threaded
http://www.securityfocus.com/archive/1/432267/100/0/threaded
http://www.securityfocus.com/bid/17590 Exploit
http://www.us-cert.gov/cas/techalerts/TA06-109A.html US Government Resource
http://www.vupen.com/english/advisories/2006/1397 Vendor Advisory
http://www.vupen.com/english/advisories/2006/1571 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/26050
https://exchange.xforce.ibmcloud.com/vulnerabilities/26054
http://secunia.com/advisories/19712 Patch Vendor Advisory
http://secunia.com/advisories/19859 Vendor Advisory
http://securitytracker.com/id?1015961 Patch
http://www.kb.cert.org/vuls/id/139049 US Government Resource
http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html
http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html
http://www.securityfocus.com/archive/1/432267/100/0/threaded
http://www.securityfocus.com/archive/1/432267/100/0/threaded
http://www.securityfocus.com/bid/17590 Exploit
http://www.us-cert.gov/cas/techalerts/TA06-109A.html US Government Resource
http://www.vupen.com/english/advisories/2006/1397 Vendor Advisory
http://www.vupen.com/english/advisories/2006/1571 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/26050
https://exchange.xforce.ibmcloud.com/vulnerabilities/26054
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*

History

21 Nov 2024, 00:09

Type Values Removed Values Added
References () http://secunia.com/advisories/19712 - Patch, Vendor Advisory () http://secunia.com/advisories/19712 - Patch, Vendor Advisory
References () http://secunia.com/advisories/19859 - Vendor Advisory () http://secunia.com/advisories/19859 - Vendor Advisory
References () http://securitytracker.com/id?1015961 - Patch () http://securitytracker.com/id?1015961 - Patch
References () http://www.kb.cert.org/vuls/id/139049 - US Government Resource () http://www.kb.cert.org/vuls/id/139049 - US Government Resource
References () http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html - () http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html -
References () http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html - () http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html -
References () http://www.securityfocus.com/archive/1/432267/100/0/threaded - () http://www.securityfocus.com/archive/1/432267/100/0/threaded -
References () http://www.securityfocus.com/bid/17590 - Exploit () http://www.securityfocus.com/bid/17590 - Exploit
References () http://www.us-cert.gov/cas/techalerts/TA06-109A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA06-109A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2006/1397 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/1397 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2006/1571 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/1571 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/26050 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/26050 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/26054 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/26054 -

Information

Published : 2006-04-20 10:02

Updated : 2024-11-21 00:09


NVD link : CVE-2006-1866

Mitre link : CVE-2006-1866

CVE.ORG link : CVE-2006-1866


JSON object : View

Products Affected

oracle

  • database_server