Vulnerabilities > CVE-2002-0965 - Unspecified vulnerability in Oracle Oracle9I 9.0/9.0.1/9.0.2

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
oracle
exploit available
metasploit

Summary

Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a log file.

Vulnerable Configurations

Part Description Count
Application
Oracle
3

Exploit-Db

descriptionOracle 8i TNS Listener SERVICE_NAME Buffer Overflow. CVE-2002-0965. Remote exploit for windows platform
idEDB-ID:16341
last seen2016-02-01
modified2010-11-24
published2010-11-24
reportermetasploit
sourcehttps://www.exploit-db.com/download/16341/
titleOracle 8i TNS Listener SERVICE_NAME Buffer Overflow

Metasploit

descriptionThis module exploits a stack buffer overflow in Oracle. When sending a specially crafted packet containing a long SERVICE_NAME to the TNS service, an attacker may be able to execute arbitrary code.
idMSF:EXPLOIT/WINDOWS/ORACLE/TNS_SERVICE_NAME
last seen2020-04-11
modified2017-07-24
published2009-07-15
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/oracle/tns_service_name.rb
titleOracle 8i TNS Listener SERVICE_NAME Buffer Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83091/tns_service_name.rb.txt
idPACKETSTORM:83091
last seen2016-12-05
published2009-11-26
reporterMC
sourcehttps://packetstormsecurity.com/files/83091/Oracle-TNS-Listener-SERVICE_NAME-Buffer-Overflow..html
titleOracle TNS Listener SERVICE_NAME Buffer Overflow.