First published: Wed Apr 18 2007(Updated: )
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact and remote authenticated attack vectors, related to (1) Change Data Capture (CDC), aka DB08, and (2) Oracle Instant Client, aka DB11. NOTE: as of 20070424, oracle has not disputed reliable claims that these issues are buffer overflows using a long CHANGE_TABLE_NAME parameter to the DBMS_CDC_IPUBLISH.CHGTAB_CACHE procedure (DB08) and Oracle Instant Client genezi utility (DB11).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =10.2.0.2 | |
Oracle Database | =10.1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-2114 is currently unknown as the specific impact of the vulnerabilities is unspecified.
To mitigate CVE-2007-2114, it is recommended to apply the latest security patch updates from Oracle for versions 10.1.0.5 and 10.2.0.2.
CVE-2007-2114 affects Oracle Database versions 10.1.0.5 and 10.2.0.2.
CVE-2007-2114 allows for remote authenticated attacks related to multiple unspecified vulnerabilities.
Yes, CVE-2007-2114 is related to vulnerabilities in Change Data Capture (CDC) and Oracle Instant Client.