CVE-2001-0943: High severity oracle database server vulnerability
dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0943?
CVE-2001-0943 is considered a high-severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2001-0943?
To fix CVE-2001-0943, ensure that the PATH environment variable does not include directories that contain untrusted or malicious executables.
Which versions of Oracle Database are affected by CVE-2001-0943?
CVE-2001-0943 affects Oracle Database versions 8.0.5 and 8.1.5.
What type of attack is associated with CVE-2001-0943?
CVE-2001-0943 is associated with local privilege escalation attacks through the execution of Trojan Horse programs.
Who is primarily affected by CVE-2001-0943?
Local users with access to modify the environment variables are primarily affected by CVE-2001-0943.