First published: Thu Nov 29 2001(Updated: )
dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious version of dbsnmp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =8.1.6 | |
Oracle Database | =8.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0942 is considered a high severity vulnerability due to its potential to allow local users to execute arbitrary programs.
To fix CVE-2001-0942, ensure that the ORACLE_HOME environment variable is correctly configured and not pointing to an untrusted directory.
Users of Oracle Database versions 8.1.6 and 8.1.7 are affected by CVE-2001-0942.
CVE-2001-0942 allows local users to perform arbitrary code execution by exploiting the misconfigured ORACLE_HOME variable.
CVE-2001-0942 is a local vulnerability, as it requires local access to the system to exploit.