CVE-2008-1820
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the Data Pump component in Oracle Database 9.2.0.8, 10.1.0.5, 10.2.0.3, and 11.1.0.6 has unknown impact and remote attack vectors related to KUPF$FILE_INT, aka DB11. NOTE: the previous information was obtained from the April 2008 CPU. Oracle has not commented on reliable researcher claims that DB11 is for a buffer overflow in the SYS.KUPF$FILE_INT.GET_FULL_FILENAME procedure.
Una vulnerabilidad no especificada en el componente Data Pump en Oracle Database versiones 9.2.0.8, 10.1.0.5, 10.2.0.3 y 11.1.0.6, presenta un impacto desconocido y vectores de ataque remotos relacionados con KUPF$FILE_INT, también se conoce como DB11. NOTA: la información anterior fue obtenida de la CPU de abril de 2008. Oracle no ha comentado sobre las afirmaciones de investigadores confiables que DB11 es para un desbordamiento de búfer en el procedimiento SYS. KUPF$FILE_INT. GET_FULL_FILENAME.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-04-15 CVE Reserved
- 2008-04-16 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpuapr2008-082075.html | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/491524/30/390/threaded | Mailing List | |
http://www.securitytracker.com/id?1019855 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41858 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42036 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/29829 | 2018-10-11 | |
http://secunia.com/advisories/29874 | 2018-10-11 | |
http://www.securityfocus.com/archive/1/491024/100/0/threaded | 2018-10-11 | |
http://www.vupen.com/english/advisories/2008/1233/references | 2018-10-11 | |
http://www.vupen.com/english/advisories/2008/1267/references | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Database 10g Search vendor "Oracle" for product "Database 10g" | 10.1.0.5 Search vendor "Oracle" for product "Database 10g" and version "10.1.0.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database 10g Search vendor "Oracle" for product "Database 10g" | 10.2.0.3 Search vendor "Oracle" for product "Database 10g" and version "10.2.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database 11g Search vendor "Oracle" for product "Database 11g" | 11.1.0.6 Search vendor "Oracle" for product "Database 11g" and version "11.1.0.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database 9i Search vendor "Oracle" for product "Database 9i" | 9.2.0.8 Search vendor "Oracle" for product "Database 9i" and version "9.2.0.8" | - |
Affected
|