20011023 FW: ASI Oracle Security Alert: 3 new security alertsmailing list
http://marc.info/?l=bugtraq&m=100386756715645&w=2 CVE-2001-0833
Oracle OTRCREP Oracle 8/9 - Home Environment Variable Buffer Overflow
Record summary
CVE-2001-0833 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOracle OTRCREP Oracle 8/9 - Home Environment Variable Buffer OverflowExploitDB exploitby Juan Manuel Pascual EscribáNot analyzed1 file
References
820010802 vulnerability in otrcrep binary in Oracle 8.0.5.mailing list
http://online.securityfocus.com/archive/1/201295 20011024 Oracle Trace Collection Security Vulnerabilitymailing list
http://online.securityfocus.com/archive/1/222612 otn.oracle.comConfirmation
http://otn.oracle.com/deploy/security/pdf/otrcrep.pdf M-011Third-party advisoryGovernment resource
http://www.ciac.org/ciac/bulletins/m-011.shtml 3139vdb entry
http://www.securityfocus.com/bid/3139 oracle-binary-symlink(6940)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6940 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0833