| Vulnerability Name: | CVE-2009-1979 (CCN-53837) | ||||||||
| Assigned: | 2009-10-21 | ||||||||
| Published: | 2009-10-21 | ||||||||
| Updated: | 2018-10-10 | ||||||||
| Summary: | Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. Note: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTH_SESSKEY parameter length that leads to arbitrary code execution. Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html # The CVSS Base Score is 10.0 only for Windows. For Linux, Unix and other platforms, the CVSS Base Score is 7.5, and the impacts for Confidentiality, Integrity and Availability are Partial+. | ||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||
| Vulnerability Consequences: | Other | ||||||||
| References: | Source: MISC Type: UNKNOWN http://blogs.conus.info/node/28 Source: MITRE Type: CNA CVE-2009-1979 Source: OSVDB Type: UNKNOWN 59110 Source: CCN Type: SA37027 Oracle Database Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 37027 Source: CCN Type: SECTRACK ID: 1023057 Oracle Database Flaws Let Remote Users Take Fully Control of the Database or System Source: CCN Type: Oracle Critical Patch Update Advisory - October 2009 Oracle Critical Patch Update Advisory - October 2009 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html Source: CCN Type: OSVDB ID: 59110 Oracle Database Network Authentication AUTH_SESSKEY Parameter Remote Overflow Source: BUGTRAQ Type: UNKNOWN 20091030 CVE-2009-1979 (Oracle RDBMS) Source: BID Type: UNKNOWN 36747 Source: CCN Type: BID-36747 Oracle Network Authentication CVE-2009-1979 Remote Buffer Overflow Vulnerability Source: SECTRACK Type: UNKNOWN 1023057 Source: CERT Type: US Government Resource TA09-294A Source: XF Type: UNKNOWN oracle-db-netauth-unspecified(53837) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||