First published: Tue Jul 17 2001(Updated: )
Format string vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Internet Directory | =2.1.1 | |
Oracle Internet Directory | =3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0974 is considered a critical vulnerability allowing remote code execution.
To fix CVE-2001-0974, upgrade Oracle Internet Directory Server to the latest version that addresses this vulnerability.
CVE-2001-0974 affects Oracle Internet Directory versions 2.1.1 and 3.0.1.
Yes, CVE-2001-0974 can be exploited remotely by attackers using crafted LDAP requests.
Exploitation of CVE-2001-0974 may lead to unauthorized access and execution of arbitrary code on the server.