CVE-2001-0833

Oracle Database Server < 9.0.1 - Buffer Overflow via ORACLE_HOME Environment Variable

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0833. PoCs published by Juan Manuel Pascual Escribá.

AI-analyzed exploit summary This exploit targets a buffer overflow in Oracle's otrcrep binary (SUID oracle, SGID dba) via the $ORACLE_HOME environment variable. It crafts a malicious environment variable to overwrite the return address and execute shellcode, granting arbitrary code execution with elevated privileges.

Description

Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Juan Manuel Pascual Escribá · clocalunix
https://www.exploit-db.com/exploits/21045

This exploit targets a buffer overflow in Oracle's otrcrep binary (SUID oracle, SGID dba) via the $ORACLE_HOME environment variable. It crafts a malicious environment variable to overwrite the return address and execute shellcode, granting arbitrary code execution with elevated privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Oracle Database 8.0.5 (otrcrep binary)
No auth needed
Prerequisites: Local access to the system · Oracle Database 8.0.5 installed with vulnerable otrcrep binary · SUID/SGID permissions on otrcrep
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=100386756715645&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3139
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/m-011.shtml
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/201295
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6940
Patch, Vendor Advisory x_refsource_confirm
http://otn.oracle.com/deploy/security/pdf/otrcrep.pdf
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/222612

Scores

EPSS 0.0215
EPSS Percentile 79.8%

Details

Status published
Products (3)
oracle/database_server 8.0
oracle/database_server 8.1
oracle/database_server < 9.0.1
Published Dec 06, 2001
Tracked Since Feb 18, 2026