CVE
- Id
- 3748
- CVE No.
- CVE-2001-0942
- Status
- Candidate
- Description
- dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious version of dbsnmp.
- Phase
- Modified (20050702)
- Votes
- ACCEPT(2) Armstrong, Foat | MODIFY(1) Frech | NOOP(2) Cole, Wall
- Comments
- Frech> XF:oracle-dbsnmp-home-validation(7645)