First published: Sun Mar 05 2000(Updated: )
The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle 8i | =8.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0206 is considered to have a high severity due to its potential for privilege escalation.
To fix CVE-2000-0206, ensure that the orainstRoot.sh file is set to the correct permissions and does not retain world-writeable settings.
Exploiting CVE-2000-0206 can allow local users to gain elevated privileges on the system.
CVE-2000-0206 affects Oracle 8i version 8.1.5 running on Linux.
A workaround for CVE-2000-0206 involves adjusting file permissions to restrict access to the orainstRoot.sh file.