Vulnerability Description
Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Application Server | All versions |
| Oracle | Collaboration Suite | - |
| Oracle | Database Server | 8.1.7.4 |
| Oracle | E-Business Suite | 11.5.1 |
| Oracle | Enterprise Manager | 9 |
| Oracle | Enterprise Manager Database Control | 10.1.2 |
| Oracle | Enterprise Manager Grid Control | 10.1.0.2 |
Related Weaknesses (CWE)
References
- http://marc.info/?l=bugtraq&m=110382345829397&w=2Mailing List
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1Broken Link
- http://www.kb.cert.org/vuls/id/316206Third Party AdvisoryUS Government Resource
- http://www.ngssoftware.com/advisories/oracle23122004.txtBroken LinkPatchVendor Advisory
- http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfBroken LinkPatchVendor Advisory
- http://www.securityfocus.com/bid/10871Broken LinkPatchThird Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlBroken LinkPatchThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18659Third Party AdvisoryVDB Entry
- http://marc.info/?l=bugtraq&m=110382345829397&w=2Mailing List
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1Broken Link
- http://www.kb.cert.org/vuls/id/316206Third Party AdvisoryUS Government Resource
- http://www.ngssoftware.com/advisories/oracle23122004.txtBroken LinkPatchVendor Advisory
- http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfBroken LinkPatchVendor Advisory
- http://www.securityfocus.com/bid/10871Broken LinkPatchThird Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlBroken LinkPatchThird Party Advisory
FAQ
What is CVE-2004-1363?
CVE-2004-1363 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
How severe is CVE-2004-1363?
CVE-2004-1363 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2004-1363?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Application Server, Oracle Collaboration Suite, Oracle Database Server, Oracle E-Business Suite, Oracle Enterprise Manager.