Vulnerability Name: | CVE-2002-0857 (CCN-9832) | ||||||||
Assigned: | 2002-08-14 | ||||||||
Published: | 2002-08-14 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2002-0857 Source: BUGTRAQ Type: UNKNOWN 20020814 Oracle Listener Control Format String Vulnerabilities (#NISR14082002) Source: CCN Type: Oracle Security Alert #40 Oracle Net Listener Vulnerabilities Source: CONFIRM Type: Patch, Vendor Advisory http://otn.oracle.com/deploy/security/pdf/2002alert40rev1.pdf Source: CCN Type: SECTRACK ID: 1005037 Oracle 9i Database Input Validation Bugs in the Oracle Net Listener Lets Remote Authenticated Users Crash the Listener, Denying Service to Database Users Source: SECTRACK Type: UNKNOWN 1005037 Source: CCN Type: US-CERT VU#301059 Oracle TNS Listener Control Utility (LSNRCTL) contains format string vulnerability Source: CERT-VN Type: US Government Resource VU#301059 Source: CCN Type: NGSSoftware Insight Security Research Advisory #NISR14082002 Oracle Listener Control Format Strings Source: MISC Type: UNKNOWN http://www.ngssoftware.com/advisories/ora-lsnrfmtstr.txt Source: CCN Type: OSVDB ID: 44553 Oracle Net Listener Listener Control Utility (LSNRCTL) Startup Format String DoS Source: CCN Type: OSVDB ID: 9475 Oracle Net Listener Listener Control Utility (LSNRCTL) listener.ora Format String DoS Source: BID Type: UNKNOWN 5460 Source: CCN Type: BID-5460 Oracle Net Listener Format String Vulnerability Source: XF Type: UNKNOWN oracle-lsnrctl-format-string(9832) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |