Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

DB:ORACLE:LINK-BOF

Severity

High

Recommended

No

Recommended Action

Drop

Category

DB

Keywords

Oracle Create Database Link Buffer Overflow

Release Date

2013/05/21

Update Number

2265

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

DB: Oracle Create Database Link Buffer Overflow


This signature detects attempts to exploit a known vulnerability in Oracle Database Server. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the targeted application.

Extended Description

It is reported that Oracle Database 10g and Oracle9i Database Server products contain multiple unspecified vulnerabilities. The reported vulnerabilities include SQL injection vulnerabilities and a buffer overflow issue. It is reported that the issues may be exploited by unprivileged users to gain DBA privileges or to execute arbitrary attacker-supplied code in the context of the affected database service. NGSSoftware has stated that further details will be released on 18th of April 2005 regarding the issues that are described in this BID. Please see the referenced message for more information.

Affected Products

  • Oracle Oracle10g Application Server 10.1.0 .0.2
  • Oracle Oracle10g Application Server 9.0.4 .0
  • Oracle Oracle10g Enterprise Edition 10.1.0 .0.2
  • Oracle Oracle10g Enterprise Edition 9.0.4 .0
  • Oracle Oracle10g Personal Edition 10.1.0 .0.2
  • Oracle Oracle10g Personal Edition 9.0.4 .0
  • Oracle Oracle10g Standard Edition 10.1.0 .0.2
  • Oracle Oracle10g Standard Edition 9.0.4 .0
  • Oracle Oracle9i Application Server 1.0.2
  • Oracle Oracle9i Application Server 1.0.2 .1s
  • Oracle Oracle9i Application Server 1.0.2 .2
  • Oracle Oracle9i Application Server 1.0.2 .2.2
  • Oracle Oracle9i Application Server 9.0.2
  • Oracle Oracle9i Application Server 9.0.2 .0.0
  • Oracle Oracle9i Application Server 9.0.2 .0.1
  • Oracle Oracle9i Application Server 9.0.2 .1
  • Oracle Oracle9i Application Server 9.0.2 .2
  • Oracle Oracle9i Application Server 9.0.2 .3
  • Oracle Oracle9i Application Server 9.0.3
  • Oracle Oracle9i Application Server 9.0.3 .1
  • Oracle Oracle9i Application Server
  • Oracle Oracle9i Client Edition 9.2.0 .0.1
  • Oracle Oracle9i Client Edition 9.2.0 .0.2
  • Oracle Oracle9i Developer Edition 9.0.4
  • Oracle Oracle9i Enterprise Edition 8.1.7
  • Oracle Oracle9i Enterprise Edition 9.0.0 .2.4
  • Oracle Oracle9i Enterprise Edition 9.0.1
  • Oracle Oracle9i Enterprise Edition 9.0.1 .4
  • Oracle Oracle9i Enterprise Edition 9.0.1 .5
  • Oracle Oracle9i Enterprise Edition 9.2.0 .0
  • Oracle Oracle9i Enterprise Edition 9.2.0 .0.1
  • Oracle Oracle9i Enterprise Edition 9.2.0 .0.3
  • Oracle Oracle9i Enterprise Edition 9.2.0 .0.5
  • Oracle Oracle9i Enterprise Edition 9.2.0.2
  • Oracle Oracle9i Lite 5.0.0 .0.0.0
  • Oracle Oracle9i Lite 5.0.0 .1.0.0
  • Oracle Oracle9i Lite 5.0.0 .2.0.0
  • Oracle Oracle9i Lite 5.0.0 .2.9.0
  • Oracle Oracle9i Personal Edition 8.1.7
  • Oracle Oracle9i Personal Edition 9.0.0 .2.4
  • Oracle Oracle9i Personal Edition 9.0.1
  • Oracle Oracle9i Personal Edition 9.0.1 .4
  • Oracle Oracle9i Personal Edition 9.0.1 .5
  • Oracle Oracle9i Personal Edition 9.2.0
  • Oracle Oracle9i Personal Edition 9.2.0 .0.1
  • Oracle Oracle9i Personal Edition 9.2.0 .0.2
  • Oracle Oracle9i Personal Edition 9.2.0 .0.3
  • Oracle Oracle9i Personal Edition 9.2.0 .0.5
  • Oracle Oracle9i Standard Edition 8.1.7
  • Oracle Oracle9i Standard Edition 9.0.0
  • Oracle Oracle9i Standard Edition 9.0.0 .2.4
  • Oracle Oracle9i Standard Edition 9.0.1
  • Oracle Oracle9i Standard Edition 9.0.1 .2
  • Oracle Oracle9i Standard Edition 9.0.1 .3
  • Oracle Oracle9i Standard Edition 9.0.1 .4
  • Oracle Oracle9i Standard Edition 9.0.1 .5
  • Oracle Oracle9i Standard Edition 9.0.2
  • Oracle Oracle9i Standard Edition 9.2.0
  • Oracle Oracle9i Standard Edition 9.2.0 .0.1
  • Oracle Oracle9i Standard Edition 9.2.0 .0.2
  • Oracle Oracle9i Standard Edition 9.2.0 .0.3
  • Oracle Oracle9i Standard Edition 9.2.0 .0.5
  • Oracle Oracle9i Standard Edition 9.2.0 .3

References

  • BugTraq: 12296
  • CVE: CVE-2003-0222
  • CVE: CVE-2005-0297

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out