Vulnerability Description
Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Database Server | <= 9.0.1 |
References
- http://marc.info/?l=bugtraq&m=100386756715645&w=2
- http://online.securityfocus.com/archive/1/201295
- http://online.securityfocus.com/archive/1/222612
- http://otn.oracle.com/deploy/security/pdf/otrcrep.pdfPatchVendor Advisory
- http://www.ciac.org/ciac/bulletins/m-011.shtml
- http://www.securityfocus.com/bid/3139
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6940
- http://marc.info/?l=bugtraq&m=100386756715645&w=2
- http://online.securityfocus.com/archive/1/201295
- http://online.securityfocus.com/archive/1/222612
- http://otn.oracle.com/deploy/security/pdf/otrcrep.pdfPatchVendor Advisory
- http://www.ciac.org/ciac/bulletins/m-011.shtml
- http://www.securityfocus.com/bid/3139
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6940
FAQ
What is CVE-2001-0833?
CVE-2001-0833 is a vulnerability with a CVSS score of 7.2 (HIGH). Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerabili...
How severe is CVE-2001-0833?
CVE-2001-0833 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0833?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Database Server.