First published: Fri Dec 03 2004(Updated: )
Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Oracle9i | =standard_9.0.2 | |
Oracle Oracle9i | =standard_9.0.1.4 | |
Oracle Oracle9i | =personal_9.2.0.1 | |
Oracle Oracle9i | =personal_9.2.0.2 | |
Oracle Oracle9i | =standard_9.0.1 | |
Oracle Oracle9i | =enterprise_9.2.0.2 | |
Oracle Oracle9i | =personal_9.2 | |
Oracle Oracle9i | =standard_9.0 | |
Oracle Oracle9i | =standard_9.2.0.1 | |
Oracle Oracle9i | =enterprise_9.0.1 | |
Oracle Oracle9i | =enterprise_9.2.0 | |
Oracle Oracle9i | =enterprise_9.2.0.1 | |
Oracle Oracle9i | =standard_9.0.1.2 | |
Oracle Oracle9i | =standard_9.0.1.3 | |
Oracle Oracle9i | =standard_9.2.0.2 | |
Oracle Oracle9i | =personal_9.0.1 | |
Oracle Oracle9i | =standard_9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1208 is considered a high-severity vulnerability due to the potential for local users to execute arbitrary code.
To fix CVE-2003-1208, update Oracle 9i to version 9.2.0.3 or later, which resolves the buffer overflow issues.
All versions of Oracle 9i prior to 9.2.0.3, including 9.0.1, 9.0.2, and 9.2.0.1, are affected by CVE-2003-1208.
CVE-2003-1208 is primarily a local vulnerability, requiring local user access to exploit the buffer overflow.
The functions involved in the exploitation of CVE-2003-1208 include TIME_ZONE, NUMTOYMINTERVAL, NUMTODSINTERVAL, and FROM_TZ.