CVE-2003-0222: Buffer Overflow
Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0222?
CVE-2003-0222 is classified as a high severity vulnerability due to its potential for causing arbitrary code execution.
How do I fix CVE-2003-0222?
To fix CVE-2003-0222, it is recommended to apply the latest patches and updates from Oracle for the affected database versions.
Which Oracle Database versions are affected by CVE-2003-0222?
CVE-2003-0222 affects Oracle Database Server 9i release 2 and earlier, including versions 8.0.x, 8.1.x, and Oracle 8i.
What types of attacks are possible due to CVE-2003-0222?
CVE-2003-0222 could allow attackers to execute arbitrary code through specially crafted "CREATE DATABASE LINK" queries.
Is it possible to mitigate CVE-2003-0222 if I cannot apply the patch immediately?
While applying patches is the best approach, temporary mitigation may include restricting database access and monitoring for suspicious activity.