Oracle Database 9i SQL Command...

- AV AC AU C I A
发布: 2004-09-07
修订: 2025-04-13

This issue corresponds to one of the unspecified vulnerabilities mentioned in BID 10871 (Oracle Multiple Unspecified Vulnerabilities) and addressed by Oracle Alert #68. The issue is being assigned its own BID due to the release of specific technical information. Reportedly Oracle Database 9i is affected by an SQL command buffer overflow vulnerability. This issue is due to a failure of the application to properly verify user-supplied string lengths prior to copying them into finite process buffers. Successful exploitation of this issue would allow a malicious user to manipulate the memory of the affected database process. This issue will ultimately facilitate arbitrary code execution with the privileges of the affected process.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息