Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown...
Vulnerability Description
Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04. NOTE: Oracle has not disputed a reliable researcher claim that this is a buffer overflow in the ADD_LOGFILE procedure for the SYS.DBMS_LOGMNR package that allows code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-0271
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/458475/100/100/threaded
- http://secunia.com/advisories/23794
- http://www.securityfocus.com/bid/22083
- http://www.appsecinc.com/resources/alerts/oracle/2007-01.shtml
- http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html
- http://osvdb.org/32910
- http://www.us-cert.gov/cas/techalerts/TA07-017A.html
- http://www.securityfocus.com/archive/1/458006/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31541
- http://securitytracker.com/id?1017522
More from oracle
View All →Affected Vendor
oracle
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.