This application requires Javascript for optimal performance.

Oracle.Database.PITRIG_DROPMETADATA.Procedure.Buffer.Overflow

Alias(es)

Oracle.Database.PITRIG.DROPMETADATA.Access

Release Date

Nov 14, 2007

Severity

medium

Impact

System compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates a buffer overflow vulnerability in Oracle 10g R2.

The vulnerability is caused by failure to check the parameters passed to the XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure. It allows remote attackers to execute arbitrary code by calling this precedure with long arguments.

Affected Products

Oracle Oracle10g Standard Edition 10.2.3
Oracle Oracle10g Standard Edition 10.2.2
Oracle Oracle10g Standard Edition 10.2.1
Oracle Oracle10g Personal Edition 10.2.3
Oracle Oracle10g Personal Edition 10.2.2
Oracle Oracle10g Personal Edition 10.2.1
Oracle Oracle10g Enterprise Edition 10.2.3
Oracle Oracle10g Enterprise Edition 10.2.2
Oracle Oracle10g Enterprise Edition 10.2.1

Recommended Actions

Currently we are not aware of any official fix for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-4517

Reference/s

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=622
http://www.frsirt.com/english/advisories/2007/3803 (FrSIRT)
http://www.securityfocus.com/bid/26374 (BugTraq)
http://www.exploit-db.com/exploits/18093/

Reference: VID-15146