CVE-2006-0550
Buffer overflow in an unspecified Oracle Client utility might allow remote attackers to execute arbitrary code or cause a denial of service.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in an unspecified Oracle Client utility might allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DBC02 from the January 2006 CPU, in which case this would be a duplicate of CVE-2006-0283. However, there are enough inconsistencies that the mapping can not be made authoritatively.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 8.23% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- oracle/oracle client
- Source
- cve@mitre.org
References
- http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf
- http://www.kb.cert.org/vuls/id/999268Patch, Third Party Advisory, US Government Resource
- http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.htmlPatch
- http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.htmlPatch
- http://www.us-cert.gov/cas/techalerts/TA06-018A.htmlPatch, Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24321
- http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf
- http://www.kb.cert.org/vuls/id/999268Patch, Third Party Advisory, US Government Resource
- http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.htmlPatch
- http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.htmlPatch
- http://www.us-cert.gov/cas/techalerts/TA06-018A.htmlPatch, Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24321
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.