Vulnerability Description
SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the debugging feature.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Database Server | 9.2.1 |
| Oracle | Oracle9I | 9.0 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0072.html
- http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20941
- http://otn.oracle.com/deploy/security/pdf/2002alert38rev1.pdfPatchVendor Advisory
- http://www.iss.net/security_center/static/9237.phpPatchVendor Advisory
- http://www.securityfocus.com/bid/5457
- http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0072.html
- http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20941
- http://otn.oracle.com/deploy/security/pdf/2002alert38rev1.pdfPatchVendor Advisory
- http://www.iss.net/security_center/static/9237.phpPatchVendor Advisory
- http://www.securityfocus.com/bid/5457
FAQ
What is CVE-2002-0856?
CVE-2002-0856 is a vulnerability with a CVSS score of 5.0 (MEDIUM). SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the debugging feature.
How severe is CVE-2002-0856?
CVE-2002-0856 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0856?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Database Server, Oracle Oracle9I.