CVE
- Id
- 2556
- CVE No.
- CVE-2000-0987
- Status
- Candidate
- Description
- Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.
- Phase
- Proposed (20001129)
- Votes
- ACCEPT(3) Cole, Frech, Mell | NOOP(2) Armstrong, Christey
- Comments
- Christey> http://archives.neohapsis.com/archives/bugtraq/2000-12/0400.html | appears to be a rediscovery of this problem. | Christey> It looks like Juan Manuel Pascual Escriba saw this issue | in a later version and re-posted, but that later post doesn"t | mention the earlier one. The exploit is almost exactly the | same, but the affected version is 8.1.7. | ADDREF BUGTRAQ:20001221 vulnerability #1 in Oracle Internet Directory 2.1.1.1 in Oracle 8.1.7 | http://archives.neohapsis.com/archives/bugtraq/2000-12/0400.html | ADDREF BUGTRAQ:20010118 Patch for Potential Buffer Overflow Vulnerabilities in Oracle Internet Directory | http://archives.neohapsis.com/archives/bugtraq/2001-01/0325.html