First published: Tue Jul 15 2008(Updated: )
Unspecified vulnerability in the Database Scheduler component in Oracle Database 10.2.0.4 and 11.1.0.6 has unknown impact and local attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is an untrusted search path issue that allows local users to gain privileges via a malicious (1) libclntsh.so or (2) libnnz10.so library.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =10.2.0.4 | |
Oracle Database Scheduler | ||
Oracle Database | =11.1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-2613 is currently unspecified, as the impact and attack vectors remain unknown.
To address CVE-2008-2613, it is recommended to apply the latest patches provided by Oracle for affected versions.
CVE-2008-2613 affects Oracle Database versions 10.2.0.4 and 11.1.0.6.
CVE-2008-2613 impacts the Database Scheduler component within Oracle Database.
Currently, there are no documented workarounds for CVE-2008-2613 apart from updating to a non-vulnerable version.