CVE-2001-0941
Oracle Database Server 8.0.6-9.0.1 - Buffer Overflow via ORACLE_HOME Environment Variable
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2001-0941. PoCs published by Juan Manuel Pascual Escribá.
AI-analyzed exploit summary This exploit targets a buffer overflow in Oracle's dbsnmp binary (version 8.1.6.0.0) by overflowing the ORACLE_HOME environment variable. It includes shellcode to execute setuid(0) followed by a shell spawn, leveraging the setuid root binary to achieve privilege escalation.
Description
Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable.
Exploits (1)
This exploit targets a buffer overflow in Oracle's dbsnmp binary (version 8.1.6.0.0) by overflowing the ORACLE_HOME environment variable. It includes shellcode to execute setuid(0) followed by a shell spawn, leveraging the setuid root binary to achieve privilege escalation.