Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2607

Overview

Vulnerability Score 6.5 6.5
CVE Id CVE-2008-2607
Last Modified 22 Oct 2012 10:48:43
Published 15 Jul 2008 07:41:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2008-2607

Summary

Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to SYS.DBMS_AQELM. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a buffer overflow that allows attackers to cause a denial of service (database corruption) and possibly execute arbitrary code via a long argument to an unspecified procedure.

Vulnerable Systems

Application

  • Oracle Advanced Queuing Component

  • Oracle Database 9i 9.2.0.8

  • Oracle Database Server 10.1.0.5

  • Oracle Database Server 10.2.0.4

  • Oracle Database Server 11.1.0.6


References

VUPEN - ADV-2008-2115

VUPEN - ADV-2008-2109

SECTRACK - 1020499

CONFIRM - http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html

SECUNIA - 31113

SECUNIA - 31087

IDEFENSE - 20080715 Oracle Database DBMS_AQELM Package Buffer Overflow Vulnerability

HP - HPSBMA02133

CONFIRM - http://www.oracle.com/technetwork/topics/security/cpujul2008-090335.html

HP - SSRT061201


Last Updated: 27 May 2016 11:01:04