CVE-2003-0894: Buffer Overflow
Published Oct 25, 2003
·Updated
Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command line argument.
Affected Software
11 affected components
Oracle Oracle9i=enterprise_9.0.1
Oracle Oracle9i=enterprise_9.2.0.4
Oracle Oracle9i=personal_9.0.1
Oracle Oracle9i=personal_9.2.0.4
Oracle Oracle9i=standard_9.0
Oracle Oracle9i=standard_9.0.1
Oracle Oracle9i=standard_9.0.1.2
Oracle Oracle9i=standard_9.0.1.3
Oracle Oracle9i=standard_9.0.1.4
Oracle Oracle9i=standard_9.0.2
Oracle Oracle9i=standard_9.2.0.4
Event History
Oct 25, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Nov 17, 2003
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0894?
CVE-2003-0894 is considered a high severity vulnerability due to its potential for local users to execute arbitrary code.
2
How do I fix CVE-2003-0894?
To fix CVE-2003-0894, upgrade Oracle 9i Database to version 9.2.0.4 or later where the vulnerability is patched.
3
What versions of Oracle are affected by CVE-2003-0894?
CVE-2003-0894 affects Oracle 9i Database versions 9.0.x and 9.2.x prior to version 9.2.0.4.
4
Can CVE-2003-0894 be exploited remotely?
CVE-2003-0894 requires local access to the affected systems to exploit the buffer overflow vulnerability.
5
What types of attacks can CVE-2003-0894 facilitate?
CVE-2003-0894 can facilitate code execution attacks allowing local users to potentially take control of the affected system.