Oracle E-Business Suite FNDWRR Buffer Overflow Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1007282 |
|
SecurityTracker URL: http://securitytracker.com/id/1007282
|
|
CVE Reference:
CAN-2003-0632
(Links to External Site)
|
Updated: Aug 4 2003
|
Original Entry Date: Jul 24 2003
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): Oracle E-Business Suite 11i, Release 1 through Release 8; Oracle Applications, All Releases
|
Description:
A buffer overflow vulnerability was reported in the Oracle E-Business Suite in the FNDWRR CGI application. A remote user can execute arbitrary code.
It is reported that a remote user can send a malformed request to cause the FNDWRR CGI program to execute arbitrary code on the system running Oracle E-Business Suite. No further details were provided.
Oracle credits Stephen Kost of Integrigy Corporation for reporting this flaw.
|
Impact:
A remote user can execute arbitrary code to gain privileges on the target system.
|
Solution:
A patch is available at:
http://metalink.oracle.com
Search on bug number 2919943 to find the patch.
A full Patch Availability Matrix is provided in the Oracle Security Alert:
http://otn.oracle.com/deploy/security/pdf/2003alert56.pdf
|
Vendor URL: otn.oracle.com/deploy/security/pdf/2003alert56.pdf (Links to External Site)
|
Cause:
Boundary error
|
Underlying OS:
Linux (Any), UNIX (AIX), UNIX (HP/UX), UNIX (SGI/IRIX), UNIX (Solaris - SunOS), UNIX (Tru64), Windows (NT), Windows (2000), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 24 Jul 2003 00:20:02 -0400
Subject: Buffer Overflow Vulnerability in Oracle E-Business Suite
|
http://otn.oracle.com/deploy/security/pdf/2003alert56.pdf
Buffer Overflow Vulnerability in Oracle E-Business Suite
Oracle Security Alert 56
Dated: July 23, 2003
Severity: 1
Versions Affected:
Oracle E-Business Suite 11i, Release 1 through Release 8
Oracle Applications, All Releases
Oracle issued a security alert warning that a remote user can send a malformed request to
cause the FNDWRR CGI program to execute arbitrary code on the system running Oracle
E-Business Suite.
A patch is available at:
http://metalink.oracle.com
Search on bug number 2919943 to find the patch.
A full Patch Availability Matrix is provided in the Oracle Security Alert.
Oracle credits Stephen Kost of Integrigy Corporation for reporting this flaw.
|
|