Vulnerability Description
Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability."
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Database Server | <= 9.0.1 |
References
- http://marc.info/?l=bugtraq&m=100386756715645&w=2
- http://otn.oracle.com/deploy/security/pdf/oracle_race.pdfPatchVendor Advisory
- http://marc.info/?l=bugtraq&m=100386756715645&w=2
- http://otn.oracle.com/deploy/security/pdf/oracle_race.pdfPatchVendor Advisory
FAQ
What is CVE-2001-0832?
CVE-2001-0832 is a vulnerability with a CVSS score of 2.1 (LOW). Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log direct...
How severe is CVE-2001-0832?
CVE-2001-0832 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0832?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Database Server.