vendor:
Secure Backup
by:
MC
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: Secure Backup
Affected Version From: 10.1.0.3
Affected Version To: 10.1.0.3
Patch Exists: YES
Related CWE: CVE-2008-5444
CPE: oracle:secure_backup
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2003 SP0/Windows XP SP3
2009
Oracle Secure Backup NDMP_CONNECT_CLIENT_AUTH Buffer Overflow
The module exploits a stack buffer overflow in Oracle Secure Backup. When sending a specially crafted NDMP_CONNECT_CLIENT_AUTH packet, an attacker may be able to execute arbitrary code.
Mitigation:
Oracle released a patch to address this vulnerability.