Description
Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Juan Manuel Pascual Escribá · clocalunix
https://www.exploit-db.com/exploits/21045
References (7)
Scores
EPSS
0.0044
EPSS Percentile
63.1%
Details
Status
published
Products (3)
oracle/database_server
8.0
oracle/database_server
8.1
oracle/database_server
< 9.0.1
Published
Dec 06, 2001
Tracked Since
Feb 18, 2026