First published: Tue Aug 20 2002(Updated: )
Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle 8i | =8.1 | |
Oracle Database | =9.2 | |
Oracle Database | =9.0 | |
Oracle Database | =7.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0857 is considered a high-severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2002-0857, ensure that your Oracle Listener Control is updated to a version that mitigates the format string vulnerability.
CVE-2002-0857 affects Oracle 8i (8.1), Oracle Database versions 9.2, 9.0, and 7.3.4.
The potential impacts of CVE-2002-0857 include unauthorized access, data corruption, or complete control of the affected Oracle DBA system.
A potential workaround for CVE-2002-0857 is to restrict access to the Oracle Listener and validate the listener.ora configuration file entries.