CVE-2004-1371
UnknownEPSS 10.77%
Last modified
CVE-2004-1371 is a vulnerability of currently unknown severity. Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.. EPSS estimates a 10.77% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Application Server | All versions |
| Oracle | Application Server | 9.0.2 |
| Oracle | Application Server | 9.0.2.0.0 |
| Oracle | Application Server | 9.0.2.0.1 |
| Oracle | Application Server | 9.0.2.1 |
| Oracle | Application Server | 9.0.2.2 |
| Oracle | Application Server | 9.0.2.3 |
| Oracle | Application Server | 9.0.3 |
| Oracle | Application Server | 9.0.3.1 |
| Oracle | Application Server | 9.0.4 |
| Oracle | Application Server | 9.0.4.0 |
| Oracle | Application Server | 9.0.4.1 |
| Oracle | Collaboration Suite | release_1 |
| Oracle | Database Server | 9i_application_server |
| Oracle | E-Business Suite | 11.5.1 |
| Oracle | E-Business Suite | 11.5.2 |
| Oracle | E-Business Suite | 11.5.3 |
| Oracle | E-Business Suite | 11.5.4 |
| Oracle | E-Business Suite | 11.5.5 |
| Oracle | E-Business Suite | 11.5.6 |
| Oracle | E-Business Suite | 11.5.7 |
| Oracle | E-Business Suite | 11.5.8 |
| Oracle | E-Business Suite | 11.5.9 |
| Oracle | Enterprise Manager | 9 |
| Oracle | Enterprise Manager | 9.0.1 |
| Oracle | Enterprise Manager Database Control | 10.1.2 |
| Oracle | Enterprise Manager Grid Control | 10.1.0.2 |
| Oracle | Oracle10g | enterprise_9.0.4_.0 |
| Oracle | Oracle10g | enterprise_10.1.0.2 |
| Oracle | Oracle10g | personal_9.0.4_.0 |
| Oracle | Oracle10g | personal_10.1_.0.2 |
| Oracle | Oracle10g | standard_9.0.4_.0 |
| Oracle | Oracle10g | standard_10.1_.0.2 |
| Oracle | Oracle8i | enterprise_8.0.5_.0.0 |
| Oracle | Oracle8i | enterprise_8.0.6_.0.0 |
| Oracle | Oracle8i | enterprise_8.0.6_.0.1 |
| Oracle | Oracle8i | enterprise_8.1.5_.0.0 |
| Oracle | Oracle8i | enterprise_8.1.5_.0.2 |
| Oracle | Oracle8i | enterprise_8.1.5_.1.0 |
| Oracle | Oracle8i | enterprise_8.1.6_.0.0 |
| Oracle | Oracle8i | enterprise_8.1.6_.1.0 |
| Oracle | Oracle8i | enterprise_8.1.7_.0.0 |
| Oracle | Oracle8i | enterprise_8.1.7_.1.0 |
| Oracle | Oracle8i | enterprise_8.1.7_.4 |
| Oracle | Oracle8i | standard_8.0.6 |
| Oracle | Oracle8i | standard_8.0.6_.3 |
| Oracle | Oracle8i | standard_8.1.5 |
| Oracle | Oracle8i | standard_8.1.6 |
| Oracle | Oracle8i | standard_8.1.7 |
| Oracle | Oracle8i | standard_8.1.7_.0.0 |
Showing 50 of 88 affected configurations. See NVD for the full list.
References
- http://www.kb.cert.org/vuls/id/316206US Government Resource
- http://www.ngssoftware.com/advisories/oracle23122004J.txtPatch, Vendor Advisory
- http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfPatch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/316206US Government Resource
- http://www.ngssoftware.com/advisories/oracle23122004J.txtPatch, Vendor Advisory
- http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfPatch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlPatch, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1371?
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
How severe is CVE-2004-1371?
Severity scoring for CVE-2004-1371 is pending analysis. The EPSS model estimates a 10.77% probability of exploitation in the next 30 days.
How do I fix CVE-2004-1371?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2004-1371?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
