vendor:
Oracle Database
by:
Esteban Martinez Fayo
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Oracle Database
Affected Version From: Oracle Database Server version 10.1.0.2
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows 2000 Server SP4
Buffer Overflow Vulnerability in Oracle Database
An attacker can supply excessive data to the 'MDSYS.MD2.SDO_CODE_SIZE' procedure, resulting in overflowing a destination buffer. This can be leveraged to execute arbitrary code and gain 'SYSDBA' privileges.
Mitigation:
Apply the available fixes provided by Oracle at http://metalink.oracle.com.