First published: Sat Aug 02 2003(Updated: )
Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and 1, and Oracle 8i, allows authenticated database users, and arbitrary database users in some cases, to execute arbitrary code via a long library name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle 8i | =standard_8.1.7_.4 | |
Oracle Oracle9i | =standard_9.0.2 | |
Oracle Oracle9i | =standard_9.0.1.4 | |
Oracle 8i | =enterprise_8.1.6_.0.0 | |
Oracle Oracle9i | =client_9.2.0.2 | |
Oracle Oracle9i | =client_9.2.0.1 | |
Oracle Oracle9i | =personal_9.2.0.1 | |
Oracle Oracle9i | =personal_9.2.0.2 | |
Oracle 8i | =enterprise_8.1.5_.1.0 | |
Oracle 8i | =standard_8.1.7_.0.0 | |
Oracle 8i | =standard_8.1.7_.1 | |
Oracle Oracle9i | =standard_9.2.0.1 | |
Oracle Oracle9i | =standard_9.2.0.2 | |
Oracle 8i | =enterprise_8.1.7_.1.0 | |
Oracle Oracle9i | =enterprise_9.0.1 | |
Oracle Oracle9i | =enterprise_9.2.0.1 | |
Oracle Oracle9i | =standard_9.0.1.2 | |
Oracle Oracle9i | =standard_9.0.1.3 | |
Oracle 8i | =enterprise_8.1.6_.1.0 | |
Oracle 8i | =enterprise_8.1.7_.0.0 | |
Oracle Oracle9i | =standard_9.0 | |
Oracle Oracle9i | =standard_9.0.1 | |
Oracle 8i | =enterprise_8.1.5_.0.0 | |
Oracle 8i | =enterprise_8.1.5_.0.2 | |
Oracle 8i | =standard_8.1.6 | |
Oracle Oracle9i | =enterprise_9.2.0.2 | |
Oracle Oracle9i | =personal_9.0.1 | |
Oracle 8i | =standard_8.1.5 | |
Oracle 8i | =standard_8.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0634 has a high severity rating due to its potential for allowing authenticated and arbitrary database users to execute arbitrary code.
To mitigate CVE-2003-0634, it is recommended to apply the relevant security patches provided by Oracle for affected versions of Oracle Database.
CVE-2003-0634 affects various versions of Oracle8i and Oracle9i, including both standard and enterprise editions.
Exploitability of CVE-2003-0634 is possible if an attacker has network access to the vulnerable Oracle database and valid authentication.
The impact of CVE-2003-0634 includes the potential for arbitrary code execution, which can compromise the integrity and confidentiality of the database.