Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2009-1979
StatusUNKNOWN
DescriptionUnspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2009 CPU.  Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTH_SESSKEY parameter length that leads to arbitrary code execution.
SeverityHigh
CVSS score10
CVSS vector(AV:N/AC:L/Au:N/C:C/I:C/A:C)
PhaseASSIGNED (17.11.2009)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1979
ReferencesBID : 36747
 BUGTRAQ : 20091030 CVE-2009-1979 (Oracle RDBMS)
 CERT : TA09-294A
 CONFIRM : http://www.oracle.com/technology/deploy/security/c...
 MISC : http://blogs.conus.info/node/28
 OSVDB : 59110
 SECTRACK : 1023057
 SECUNIA : 37027
SecurityVulns:Oracle multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server