Short Name |
DB:ORACLE:TNS:TABLEFUNC-ASOWN |
|---|---|
Severity |
High |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
DB |
Keywords |
Oracle Database CTXSYS.DRVDISP.TABLEFUNC_ASOWN Buffer Overflow BO DB |
Release Date |
2011/12/14 |
Update Number |
2047 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+ |
A buffer overflow vulnerability exists in Oracle's Database server. The vulnerability is due to the way in which parameters are handled by the TABLEFUNC_ASOWN function in the CTXSYS.DRVDISP package. A remote, authenticated attacker could exploit this vulnerability to execute arbitrary code on the target server, in the security context of the Oracle Database service, normally SYSTEM on Windows platforms and an unprivileged user on Unix platforms.
Oracle Database is prone to a buffer-overflow vulnerability that exists in Oracle Text. The vulnerability can be exploited over the 'Oracle Net' protocol. For an exploit to succeed, the attacker must have 'Execute on CTXSYS.DRVDISP' privileges. Successful exploits will allow attackers to execute arbitrary code in the context of the affected application. This may facilitate a complete system compromise. This vulnerability affects the following supported versions: 10.1.0.5, 10.2.0.3, 10.2.0.4, 11.1.0.7ww