CVE-2004-1774: Buffer Overflow
Published Aug 31, 2004
·Updated
Buffer overflow in the SDOCODESIZE procedure of the MD2 package (MDSYS.MD2.SDOCODESIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.
Affected Software
4 affected components
Oracle Application Server=10.1.0.2
Oracle Oracle10g=enterprise_10.1.0.2
Oracle Oracle10g=personal_10.1.0.2
Oracle Oracle10g=standard_10.1.0.2
Remediation
Patch Available
Event History
Aug 31, 2004
CVE Published
04:00 AM
Apr 19, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1774?
CVE-2004-1774 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2004-1774?
To fix CVE-2004-1774, update to Oracle 10g version 10.1.0.2 Patch 2 or later.
3
Who is affected by CVE-2004-1774?
CVE-2004-1774 affects local users of Oracle 10g versions prior to 10.1.0.2 Patch 2.
4
What type of vulnerability is CVE-2004-1774?
CVE-2004-1774 is a buffer overflow vulnerability in the SDO_CODE_SIZE procedure.
5
What can attackers do with CVE-2004-1774?
Attackers can execute arbitrary code on affected systems by exploiting the buffer overflow in CVE-2004-1774.