CVE-2003-0096: Buffer Overflow
Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TOTIMESTAMPTZ function, (2) a long time zone argument to the TZOFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0096?
CVE-2003-0096 is considered to have a high severity due to the potential for remote code execution.
How do I fix CVE-2003-0096?
To fix CVE-2003-0096, you should apply the latest patches provided by Oracle for the affected versions of the Oracle database.
What software versions are affected by CVE-2003-0096?
CVE-2003-0096 affects multiple versions of Oracle 9i and 8i Database including versions 9.0.1, 9.0.2, and 8.1.7.
What types of attacks are possible with CVE-2003-0096?
CVE-2003-0096 allows remote attackers to execute arbitrary code through specific functions with oversized inputs.
How widespread is CVE-2003-0096?
CVE-2003-0096 has been noted in multiple security reports, indicating a significant risk for systems utilizing the affected Oracle database versions.