CVE-2003-0222
Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.
- CVSS 2.0
- 9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 11.04% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- oracle/database server · oracle/oracle8i · oracle/oracle9i
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=105162831008176&w=2
- http://marc.info/?l=ntbugtraq&m=105163376015735&w=2
- http://otn.oracle.com/deploy/security/pdf/2003alert54.pdfPatch, Vendor Advisory
- http://www.ciac.org/ciac/bulletins/n-085.shtml
- http://www.securityfocus.com/bid/7453Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11885
- http://marc.info/?l=bugtraq&m=105162831008176&w=2
- http://marc.info/?l=ntbugtraq&m=105163376015735&w=2
- http://otn.oracle.com/deploy/security/pdf/2003alert54.pdfPatch, Vendor Advisory
- http://www.ciac.org/ciac/bulletins/n-085.shtml
- http://www.securityfocus.com/bid/7453Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11885
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.