First published: Wed Jan 17 2007(Updated: )
Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04. NOTE: Oracle has not disputed a reliable researcher claim that this is a buffer overflow in the ADD_LOGFILE procedure for the SYS.DBMS_LOGMNR package that allows code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =9.0.1.5 | |
Oracle Database | =9.2.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-0271 is currently unspecified, but it may involve a critical buffer overflow vulnerability.
To fix CVE-2007-0271, it is recommended to update Oracle Database to a version where this vulnerability is patched.
CVE-2007-0271 affects Oracle Database versions 9.0.1.5 and 9.2.0.7.
CVE-2007-0271 is related to the Log Miner component and sys.dbms_log_mnr privileges.
The specific attack vectors for CVE-2007-0271 are unknown, but it has been linked to a buffer overflow vulnerability.