Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=100386756715645&w=2 | mailing list |
http://www.securityfocus.com/bid/3139 | vdb entry |
http://www.ciac.org/ciac/bulletins/m-011.shtml | third party advisory government resource |
http://online.securityfocus.com/archive/1/201295 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6940 | vdb entry |
http://otn.oracle.com/deploy/security/pdf/otrcrep.pdf | patch vendor advisory |
http://online.securityfocus.com/archive/1/222612 | mailing list |