Vulnerabilities > CVE-2001-0499 - Buffer Overflow vulnerability in Oracle 8i TNS Listener
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Oracle 8i TNS Listener (ARGUMENTS) Buffer Overflow. CVE-2001-0499. Remote exploit for windows platform id EDB-ID:16340 last seen 2016-02-01 modified 2010-11-24 published 2010-11-24 reporter metasploit source https://www.exploit-db.com/download/16340/ title Oracle 8i TNS Listener ARGUMENTS Buffer Overflow description Oracle 8i TNS Listener Buffer Overflow Vulnerability. CVE-2001-0499. Remote exploit for windows platform id EDB-ID:20980 last seen 2016-02-02 modified 2001-07-20 published 2001-07-20 reporter benjurry source https://www.exploit-db.com/download/20980/ title Oracle 8i TNS Listener Buffer Overflow Vulnerability
Metasploit
description | This module exploits a stack buffer overflow in Oracle 8i. When sending a specially crafted packet containing an overly long ARGUMENTS string to the TNS service, an attacker may be able to execute arbitrary code. |
id | MSF:EXPLOIT/WINDOWS/ORACLE/TNS_ARGUMENTS |
last seen | 2020-05-22 |
modified | 2017-09-14 |
published | 2009-07-13 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0499 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/oracle/tns_arguments.rb |
title | Oracle 8i TNS Listener (ARGUMENTS) Buffer Overflow |
Packetstorm
data source | https://packetstormsecurity.com/files/download/83067/tns_arguments.rb.txt |
id | PACKETSTORM:83067 |
last seen | 2016-12-05 |
published | 2009-11-26 |
reporter | MC |
source | https://packetstormsecurity.com/files/83067/Oracle-8i-TNS-Listener-ARGUMENTS-Buffer-Overflow..html |
title | Oracle 8i TNS Listener (ARGUMENTS) Buffer Overflow. |