CVE-2001-0974: High severity oracle internet directory vulnerability
Published Jul 17, 2001
·Updated
Format string vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
Affected Software
2 affected components
Oracle Internet Directory=2.1.1
Oracle Internet Directory=3.0.1
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jul 17, 2001
CVE Published
04:00 AM
Feb 2, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0974?
CVE-2001-0974 is considered a critical vulnerability allowing remote code execution.
2
How do I fix CVE-2001-0974?
To fix CVE-2001-0974, upgrade Oracle Internet Directory Server to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2001-0974?
CVE-2001-0974 affects Oracle Internet Directory versions 2.1.1 and 3.0.1.
4
Can CVE-2001-0974 be exploited remotely?
Yes, CVE-2001-0974 can be exploited remotely by attackers using crafted LDAP requests.
5
What are the potential consequences of CVE-2001-0974?
Exploitation of CVE-2001-0974 may lead to unauthorized access and execution of arbitrary code on the server.