Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2007-2110
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-2110

Description:
Unspecified vulnerability in the Core RDBMS component for Oracle Database 9.0.1.5 and 10.1.0.4 on Windows systems has unknown impact and attack vectors, aka DB03. NOTE: as of 20070424, Oracle has not disputed reliable claims that DB03 occurs because RDBMS uses a NULL Discretionary Access Control List (DACL) for the Oracle process and certain shared memory sections, which allows local users to inject threads and execute arbitrary code via the OpenProcess, OpenThread, and SetThreadContext functions (DB03).

CVE Status:
Candidate

References:

ST
  1017927

MLIST
  http://www.freelists.org/archives/oracle-l/12-2006/msg00004.html

MISC
  http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf
  http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html
  http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf

HP
  http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded

CONFIRM
  http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html

CERT
  http://www.us-cert.gov/cas/techalerts/TA07-108A.html

BID
  23532


Return to the previous page.