CVE-2006-1876: SQL Injection
Unspecified vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.4 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB12. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the (1) GENRIDRANGEBYAREA and (2) GENRIDRANGE functions in the MDSYS.SDOPRIDX package.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1876?
The severity of CVE-2006-1876 is not clearly defined due to the unspecified nature of the vulnerability.
How do I fix CVE-2006-1876?
To address CVE-2006-1876, the recommended action is to upgrade to a more recent version of the Oracle Database Server.
What versions of Oracle Database are affected by CVE-2006-1876?
CVE-2006-1876 affects Oracle Database Server versions 9.2.0.7 and 10.1.0.4.
Is there a public statement from Oracle regarding CVE-2006-1876?
As of April 2006, Oracle has not publicly disputed the claims regarding CVE-2006-1876.
What component of Oracle Database is impacted by CVE-2006-1876?
CVE-2006-1876 impacts the Oracle Spatial component of the Oracle Database.