CVE-2007-1442: High severity Oracle Database Server vulnerability
Published Mar 14, 2007
·Updated
Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACLs), which allows local users to gain privileges.
Affected Software
9 affected components
Oracle Database Server=10.2.1
Oracle Database Server=10.2.1
Oracle Database Server=10.2.1
Oracle Database Server=10.2.2
Oracle Database Server=10.2.2
Oracle Database Server=10.2.2
Oracle Database Server=10.2.3
Oracle Database Server=10.2.3
Oracle Database Server=10.2.3
Event History
Mar 14, 2007
CVE Published
12:19 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1442?
CVE-2007-1442 is considered a high-severity vulnerability due to the potential for local privilege escalation.
2
How do I fix CVE-2007-1442?
To fix CVE-2007-1442, apply the relevant security patches provided by Oracle for affected versions of the Oracle Database.
3
Which versions of Oracle Database are affected by CVE-2007-1442?
CVE-2007-1442 affects Oracle Database versions 10.2.1, 10.2.2, and 10.2.3.
4
What type of vulnerability is CVE-2007-1442?
CVE-2007-1442 is a local privilege escalation vulnerability affecting Oracle Database.
5
Can CVE-2007-1442 be exploited remotely?
No, CVE-2007-1442 requires local access to the system to exploit the vulnerability.