First published: Wed Jan 17 2007(Updated: )
Multiple unspecified vulnerabilities in Oracle Database 9.2.0.7 and 10.1.0.5 have unknown impact and attack vectors related to (1) Export and sys.dbms_logrep_util (DB08), and (2) Oracle Streams and sys.dbms_capture_adm_internal privileges (DB09). NOTE: Oracle has not disputed reliable researcher claims that DB08 is for a buffer overflow in the GET_OBJECT_NAME procedure in the DBMS_LOGREP_UTIL package, and DB09 is for buffer overflows in the CREATE_CAPTURE, ALTER_CAPTURE, and ABORT_TABLE_INSTANTIATION procedures in SYS.DBMS_CAPTURE_ADM_INTERNAL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =9.2.0.7 | |
Oracle Database | =10.1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-0274 remains unspecified due to unknown impact and attack vectors.
CVE-2007-0274 affects Oracle Database versions 9.2.0.7 and 10.1.0.5.
Currently, there are no specific patches or fixes documented for CVE-2007-0274.
Potential risks may include exploitation of unspecified vulnerabilities affecting export and privilege management features.
There is no public information indicating that CVE-2007-0274 is actively being exploited at this time.