7.2
CVSSv2

CVE-2001-0833

Published: 06/12/2001 Updated: 03/05/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in otrcrep in Oracle 8.0.x up to and including 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

oracle database server

oracle database server 8.0

oracle database server 8.1

Exploits

source: wwwsecurityfocuscom/bid/3139/info Oracle is an Enterprise level SQL database, supporting numerous features and options It is distributed and maintained by Oracle Corporation A buffer overflow has been discovered in the handling of $ORACLE_HOME by otrcrep otrcrep is installed with the Oracle suite as a SUID oracle SGID dba bina ...