vendor:
Oracle 8i
by:
The Itch / Promisc
7.2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Oracle 8i
Affected Version From: Oracle 8i for Linux
Affected Version To: Oracle 8i for Linux
Patch Exists: YES
Related CWE: N/A
CPE: oracle:oracle8i
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2002
Oracle 8i Local Buffer Overflow Vulnerability
A vulnerability has been reported with some versions of Oracle 8i for Linux. A local attacker able to execute the tnslsnr process may pass an oversized command line parameter and cause a buffer overflow, possibly leading to the execution of arbitrary code as the user 'oracle'.
Mitigation:
Upgrade to the latest version of Oracle 8i