First published: Wed Jan 17 2007(Updated: )
Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via unspecified vectors involving certain public procedures, aka DB05.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =8.1.7.4 | |
Oracle Database | =9.0.1.5 | |
Oracle Database | =9.2.0.7 | |
Oracle Database | =10.1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0272 has a critical severity level as it allows remote authenticated users to execute arbitrary code or cause a denial of service.
To fix CVE-2007-0272, upgrade to a later version of Oracle Database that is not vulnerable to this buffer overflow issue.
CVE-2007-0272 affects users of Oracle Database versions 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4.
Exploiting CVE-2007-0272 could lead to a denial of service condition or execution of arbitrary code on the affected database.
CVE-2007-0272 describes multiple buffer overflow vulnerabilities in the MDSYS.MD package of Oracle Database.