CVE-2003-0222

Description

Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a CREATE DATABASE LINK query containing a connect string with a long USING parameter.

Risk Information

Base Score
9.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
12.51

Associated Vulnerability

VulnerabilityOS Platform
Update Oracle to 2760879Windows
Update Oracle to 2845564Windows
Update Oracle to 2784635Windows
Update Oracle to 2899111Windows
Update Oracle to 2760944Windows
Update Oracle to 2749511Windows
Vulnerabilities CVE-1999-0784,CVE-1999-0888,CVE-2003-0222,CVE-2005-3641 are affected in Oracle 7.3.3Windows
Vulnerabilities CVE-1999-0888,CVE-2002-0857,CVE-2003-0222,CVE-2005-3641 are affected in Oracle 7.3.4Windows
Vulnerabilities CVE-2002-0567,CVE-2003-0222,CVE-2005-3641 are affected in Oracle 8.0.1Windows
Vulnerabilities CVE-2002-0567,CVE-2003-0222,CVE-2005-3641 are affected in Oracle 8.0.2Windows
Vulnerabilities CVE-2002-0567,CVE-2003-0222,CVE-2005-3641 are affected in Oracle 8.0.3Windows
Vulnerabilities CVE-2002-0567,CVE-2003-0222,CVE-2005-3641 are affected in Oracle 8.0.4Windows
Vulnerabilities CVE-2001-0943,CVE-2002-0567,CVE-2003-0222,CVE-2005-3641 are affected in Oracle 8.0.5Windows
Vulnerabilities CVE-2002-0567,CVE-2003-0222,CVE-2005-3641 are affected in Oracle 8.0.5.1Windows
Multiple Vulnerabilities are affected in Oracle 8.0.6Windows
Multiple Vulnerabilities are affected in Oracle 8.1.5Windows
Multiple Vulnerabilities are affected in Oracle 8.1.6Windows
Multiple Vulnerabilities are affected in Oracle 8.1.7Windows
Vulnerabilities CVE-2002-0856,CVE-2003-0095,CVE-2003-0096,CVE-2003-0222 are affected in Oracle 9.2.1Windows
Vulnerabilities CVE-2003-0095,CVE-2003-0096,CVE-2003-0222 are affected in Oracle 9.2.2Windows
Vulnerabilities CVE-1999-0784,CVE-1999-0888,CVE-2003-0222,CVE-2005-3641 are affected in Oracle Database Server 7.3.3Windows
Vulnerabilities CVE-1999-0888,CVE-2002-0857,CVE-2003-0222,CVE-2005-3641 are affected in Oracle Database Server 7.3.4Windows
Multiple Vulnerabilities are affected in Oracle Database Server 8.1.7Windows
Multiple Vulnerabilities are affected in Oracle Database Server 8.0.6Windows
Multiple Vulnerabilities are affected in Oracle Database Server 8.1.6Windows
Vulnerabilities CVE-2001-0943,CVE-2002-0567,CVE-2003-0222,CVE-2005-3641 are affected in Oracle Database Server 8.0.5Windows
Multiple Vulnerabilities are affected in Oracle Database Server 8.1.5Windows
Vulnerabilities CVE-2002-0567,CVE-2003-0222,CVE-2005-3641 are affected in Oracle Database Server 8.0.1Windows
Vulnerabilities CVE-2002-0567,CVE-2003-0222,CVE-2005-3641 are affected in Oracle Database Server 8.0.2Windows
Vulnerabilities CVE-2002-0567,CVE-2003-0222,CVE-2005-3641 are affected in Oracle Database Server 8.0.3Windows
Vulnerabilities CVE-2002-0567,CVE-2003-0222,CVE-2005-3641 are affected in Oracle Database Server 8.0.4Windows
Vulnerabilities CVE-2002-0567,CVE-2003-0222,CVE-2005-3641 are affected in Oracle Database Server 8.0.5.1Windows
Vulnerabilities CVE-2002-0856,CVE-2003-0095,CVE-2003-0096,CVE-2003-0222 are affected in Oracle Database Server 9.2.1Windows
Vulnerabilities CVE-2003-0095,CVE-2003-0096,CVE-2003-0222 are affected in Oracle Database Server 9.2.2Windows
Update Oracle to 2760879 (For Linux)Linux
Update Oracle to 2845564 (For Linux)Linux
Update Oracle to 2784635 (For Linux)Linux
Update Oracle to 2899111 (For Linux)Linux
Update Oracle to 2760944 (For Linux)Linux
Update Oracle to 2749511 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234