CVE-2006-5345: Critical severity Oracle Database Server vulnerability
Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unknown impact and remote authenticated attack vectors related to mdsys.sdogeom, aka Vuln# DB22. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB22 is related to "length checking" in the RELATE function before MD2.RELATE is called.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5345?
CVE-2006-5345 has an unspecified severity level but is known to allow remote authenticated attackers to exploit unknown impacts.
How do I fix CVE-2006-5345?
To address CVE-2006-5345, ensure that you apply the relevant patches provided by Oracle for affected versions of the Oracle Database.
Which Oracle Database versions are affected by CVE-2006-5345?
CVE-2006-5345 affects Oracle Database versions 9.0.1.5, 9.2.0.7, and 10.1.0.4.
What components are involved in CVE-2006-5345?
CVE-2006-5345 involves the Oracle Spatial component specifically related to mdsys.sdo_geom.
What type of attacks are possible with CVE-2006-5345?
CVE-2006-5345 enables remote authenticated attack vectors, allowing potential exploitation of the vulnerability.