|
![]() ![]() |
CERT® Advisory CA-2003-05 Multiple Vulnerabilities in Oracle ServersOriginal release date: February 19, 2003Last revised: Fri Feb 21 15:39:12 EST 2003 Source: CERT/CC A complete revision history can be found at the end of this file. Systems Affected
OverviewMultiple vulnerabilities exist in Oracle software that may lead to execution of arbitrary code; the ability to read, modify, or delete information stored in underlying Oracle databases; or denial of service. All of these vulnerabilites were discovered by Next Generation Security Software Ltd. I. DescriptionMultiple vulnerabilities exist in Oracle software products. The majority of these vulnerabilities are buffer overflows. Oracle has published Security Alerts describing these vulnerabilities. If you use Oracle products listed in the "Systems Affected" section of this document, we strongly encourage you to review the following Oracle Security Alerts and apply patches as appropriate:
The CERT/CC has published vulnerability notes for each of these issues as well. The vulnerability in Oracle's mod_dav module (VU#849993) has been as assigned CVE ID CAN-2002-0842. II. ImpactDepending on the vulnerability being exploited, an attacker may be able to execute arbitrary code; read, modify, or delete information stored in underlying Oracle databases; or cause a denial of service. The vulnerabilities in "ORACLE.EXE" (VU#953746) and the WebDAV modules (VU#849993, VU#511194) may be exploited prior to authentication.III. SolutionApply a patchSolutions for specific vulnerabilities can be found in the above referenced Oracle Security Alerts, NGSSoftware Insight Security Research Advisories, and individual CERT/CC Vulnerability Notes.Mitigation StrategiesUntil a patch can be applied, the CERT/CC recommends that vulnerable sites
Appendix A. Vendor InformationThis appendix contains information provided by vendors. When vendors report new information, this section is updated and the changes are noted in the revision history. If a vendor is not listed below, we have not received their comments. Oracle Corporation
Appendix B. References
The CERT/CC acknowledges both Next Generation Security Software Ltd. and Oracle for providing information upon which this document is based. Feedback can be directed to the author: Ian A. Finlay. This document is available from: http://www.cert.org/advisories/CA-2003-05.html CERT/CC Contact Information
Phone: +1 412-268-7090 (24-hour hotline) Fax: +1 412-268-6989 Postal address: CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4) Monday through Friday; they are on call for emergencies during other hours, on U.S. holidays, and on weekends. Using encryptionWe strongly urge you to encrypt sensitive information sent by email. Our public PGP key is available from If you prefer to use DES, please call the CERT hotline for more information. Getting security informationCERT publications and other security information are available from our web site
To subscribe to the CERT mailing list for advisories and bulletins, send email to
majordomo@cert.org. Please include in the body of your
message subscribe cert-advisory * "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.
NO WARRANTY Conditions for use, disclaimers, and sponsorship information
Copyright 2003 Carnegie Mellon University. Revision History February 19, 2003: Initial release February 21, 2003: Revised description |








