CVE-2009-1979: Critical severity Oracle Database Server vulnerability
Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTHSESSKEY parameter length that leads to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1979?
The severity of CVE-2009-1979 is considered significant due to its potential impact on confidentiality, integrity, and availability.
How do I fix CVE-2009-1979?
To fix CVE-2009-1979, it is recommended to upgrade Oracle Database to a supported version that addresses the vulnerability.
Which versions of Oracle Database are affected by CVE-2009-1979?
CVE-2009-1979 affects Oracle Database versions 10.1.0.5 and 10.2.0.4.
Can CVE-2009-1979 be exploited remotely?
Yes, CVE-2009-1979 can be exploited remotely by attackers to compromise the affected database.
What are the potential impacts of CVE-2009-1979?
The potential impacts of CVE-2009-1979 include unauthorized access and modification of data, leading to possible data breaches.