vendor:
Oracle
by:
Juan Manuel Pascual
7.2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Oracle
Affected Version From: Oracle 8.1.6.0.0
Affected Version To: Oracle 8.1.6.0.0
Patch Exists: YES
Related CWE: N/A
CPE: oracle:oracle_8.1.6.0.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2002
Oracle ORACLE_HOME Environment Variable Buffer Overflow Vulnerability
When the ORACLE_HOME environment variable is filled with 750 bytes or more, a buffer overflow occurs. This overflow may be used to overwrite variables on the stack, including the return address. Since the dbsnmp program is setuid root, it is possible to gain elevated privileges, including administrative access.
Mitigation:
The user must be in the oracle group to exploit this vulnerability.