CVE-2007-2110

Unspecified vulnerability in the Core RDBMS component for Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.4 on Windows systems has unknown impact and attack vectors, aka DB03. NOTE: as of 20070424, Oracle has not disputed reliable claims that DB03 occurs because RDBMS uses a NULL Discretionary Access Control List (DACL) for the Oracle process and certain shared memory sections, which allows local users to inject threads and execute arbitrary code via the OpenProcess, OpenThread, and SetThreadContext functions (DB03).
References
Link Resource
http://www.freelists.org/archives/oracle-l/12-2006/msg00004.html
http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf
http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf
http://www.oracle.com/technetwork/topics/security/cpuapr2007-090632.html
http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html
http://www.securityfocus.com/archive/1/466329/100/200/threaded
http://www.securityfocus.com/archive/1/466329/100/200/threaded
http://www.securityfocus.com/bid/23532
http://www.securitytracker.com/id?1017927
http://www.us-cert.gov/cas/techalerts/TA07-108A.html US Government Resource
http://www.vupen.com/english/advisories/2007/1426 Vendor Advisory
https://www.blackhat.com/presentations/bh-dc-07/Cerrudo/Presentation/bh-dc-07-Cerrudo-ppt.pdf
http://www.freelists.org/archives/oracle-l/12-2006/msg00004.html
http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf
http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf
http://www.oracle.com/technetwork/topics/security/cpuapr2007-090632.html
http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html
http://www.securityfocus.com/archive/1/466329/100/200/threaded
http://www.securityfocus.com/archive/1/466329/100/200/threaded
http://www.securityfocus.com/bid/23532
http://www.securitytracker.com/id?1017927
http://www.us-cert.gov/cas/techalerts/TA07-108A.html US Government Resource
http://www.vupen.com/english/advisories/2007/1426 Vendor Advisory
https://www.blackhat.com/presentations/bh-dc-07/Cerrudo/Presentation/bh-dc-07-Cerrudo-ppt.pdf
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:oracle:database_server:10.1.0.4:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:29

Type Values Removed Values Added
References () http://www.freelists.org/archives/oracle-l/12-2006/msg00004.html - () http://www.freelists.org/archives/oracle-l/12-2006/msg00004.html -
References () http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf - () http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf -
References () http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf - () http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf -
References () http://www.oracle.com/technetwork/topics/security/cpuapr2007-090632.html - () http://www.oracle.com/technetwork/topics/security/cpuapr2007-090632.html -
References () http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html - () http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html -
References () http://www.securityfocus.com/archive/1/466329/100/200/threaded - () http://www.securityfocus.com/archive/1/466329/100/200/threaded -
References () http://www.securityfocus.com/bid/23532 - () http://www.securityfocus.com/bid/23532 -
References () http://www.securitytracker.com/id?1017927 - () http://www.securitytracker.com/id?1017927 -
References () http://www.us-cert.gov/cas/techalerts/TA07-108A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA07-108A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2007/1426 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/1426 - Vendor Advisory
References () https://www.blackhat.com/presentations/bh-dc-07/Cerrudo/Presentation/bh-dc-07-Cerrudo-ppt.pdf - () https://www.blackhat.com/presentations/bh-dc-07/Cerrudo/Presentation/bh-dc-07-Cerrudo-ppt.pdf -

Information

Published : 2007-04-18 18:19

Updated : 2024-11-21 00:29


NVD link : CVE-2007-2110

Mitre link : CVE-2007-2110

CVE.ORG link : CVE-2007-2110


JSON object : View

Products Affected

microsoft

  • windows

oracle

  • database_server