CVE-2006-5344: Buffer Overflow
Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo3gl, aka Vuln# DB20, and (2) mdsys.sdocs, aka DB21. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB20 is a buffer overflow in GEOMOPERATION, and DB21 is related to a buffer overflow and SQL injection in TRANSFORMLAYER.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5344?
The severity of CVE-2006-5344 is currently unknown due to unspecified vulnerabilities in the Oracle Spatial component.
How do I fix CVE-2006-5344?
To fix CVE-2006-5344, it is recommended to apply the latest patches provided by Oracle for affected database versions.
Which versions of Oracle Database are affected by CVE-2006-5344?
CVE-2006-5344 affects Oracle Database versions 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4.
Is remote access needed to exploit CVE-2006-5344?
Yes, CVE-2006-5344 has remote authenticated attack vectors, meaning remote access is required to exploit the vulnerabilities.
Are there any workarounds for CVE-2006-5344?
Currently, there are no publicly documented workarounds for CVE-2006-5344 other than applying the appropriate patches.