vendor:
Hyperion Performance Management and BI
by:
Anonymous
9.3
CVSS
HIGH
Stack Based Buffer Overflow
119
CWE
Product Name: Hyperion Performance Management and BI
Affected Version From: 11.1.2.1.0
Affected Version To: 11.1.2.1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:oracle:hyperion_performance_management_and_bi:11.1.2.1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows 2k3 r2 sp2
2018
Oracle DataDirect Multiple Native Wire Protocol ODBC Drivers HOST Attribute Stack Based Buffer Overflow Vulnerability
The mentioned product installs various drivers to allow the software to get informations from ODBC data sources. Some of them are vulnerable to a remote stack based buffer overflow which can be triggered by specifying an overlong HOST attribute inside the connection string. The software tries to do an unicode/ASCII conversion. In doing this, the stack is completely smashed allowing to redirect the execution flow to an user supplied buffer.
Mitigation:
Ensure that the HOST attribute is not overlong and is properly validated.