CVE Vulnerabilities

CVE-2002-0857

Published: Sep 05, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.

Affected Software

NameVendorStart VersionEnd Version
Database_serverOracle7.3.4 (including)7.3.4 (including)
Database_serverOracle9.0 (including)9.0 (including)
Database_serverOracle9.2 (including)9.2 (including)
Oracle8iOracle8.1 (including)8.1 (including)

References