CVE-2002-0857: High severity Oracle Database Server vulnerability
Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0857?
CVE-2002-0857 is considered a high-severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2002-0857?
To fix CVE-2002-0857, ensure that your Oracle Listener Control is updated to a version that mitigates the format string vulnerability.
What versions are affected by CVE-2002-0857?
CVE-2002-0857 affects Oracle 8i (8.1), Oracle Database versions 9.2, 9.0, and 7.3.4.
What are the potential impacts of CVE-2002-0857?
The potential impacts of CVE-2002-0857 include unauthorized access, data corruption, or complete control of the affected Oracle DBA system.
Is there a workaround for CVE-2002-0857?
A potential workaround for CVE-2002-0857 is to restrict access to the Oracle Listener and validate the listener.ora configuration file entries.