CVE-2000-0206: Medium severity oracle oracle8i vulnerability

Published Mar 5, 2000
·
Updated

The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges.

Affected Software

1 affected component
Oracle Oracle8i=8.1.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    After installation, remove the world-writeable permission from orainstRoot.sh so it is not writable by all users (for example: chmod 700 /path/to/orainstRoot.sh). Ensure only authorized administrative accounts can modify this file.

    Oracle Database 8.1.5.x installer (orainstRoot.sh) file_permissions = remove world-writable
  2. Compensating control

    During installation, ensure installation directories are not writable by unprivileged users and perform installations from a secure administrative account. Restrict the ability of local users to create symlinks or write in Oracle installation directories until a vendor fix is available.

  3. Operational

    Scan Linux systems for orainstRoot.sh files created by Oracle 8.1.5.x. For any instances found with world-writable permissions, immediately remove the world-writable bit (chmod as above), review the file and system for signs of unauthorized modification or privilege escalation, and remediate any compromises.

Event History

Mar 5, 2000
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Apr 25, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0206?

CVE-2000-0206 is considered to have a high severity due to its potential for privilege escalation.

2

How do I fix CVE-2000-0206?

To fix CVE-2000-0206, ensure that the orainstRoot.sh file is set to the correct permissions and does not retain world-writeable settings.

3

What are the potential impacts of exploiting CVE-2000-0206?

Exploiting CVE-2000-0206 can allow local users to gain elevated privileges on the system.

4

Which versions of Oracle are affected by CVE-2000-0206?

CVE-2000-0206 affects Oracle 8i version 8.1.5 running on Linux.

5

Is there a workaround for CVE-2000-0206?

A workaround for CVE-2000-0206 involves adjusting file permissions to restrict access to the orainstRoot.sh file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203