HIGH · 7.2

CVE-2004-1774

Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER paramete...

Vulnerability Description

Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
OracleApplication Server10.1.0.2
OracleOracle10Genterprise_10.1.0.2

References

FAQ

What is CVE-2004-1774?

CVE-2004-1774 is a vulnerability with a CVSS score of 7.2 (HIGH). Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER paramete...

How severe is CVE-2004-1774?

CVE-2004-1774 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-1774?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Application Server, Oracle Oracle10G.