CVE-2001-0833: Buffer Overflow
Published Dec 6, 2001
·Updated
Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLEHOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."
Affected Software
3 affected components
Oracle Database Server<=9.0.1
Oracle Database Server=8.0
Oracle Database Server=8.1
Remediation
Patch Available
Event History
Dec 6, 2001
CVE Published
05:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0833?
CVE-2001-0833 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2001-0833?
To fix CVE-2001-0833, upgrade to Oracle Database version 9.0.2 or later.
3
Who is affected by CVE-2001-0833?
CVE-2001-0833 affects local users of Oracle Database versions 8.0.x through 9.0.1.
4
What is the nature of the vulnerability in CVE-2001-0833?
CVE-2001-0833 is a buffer overflow vulnerability that can be exploited through a long ORACLE_HOME environment variable.
5
Can CVE-2001-0833 be exploited by remote attackers?
No, CVE-2001-0833 can only be exploited by local users who have access to the system.