CVE Database
/

CVE-2009-1979

Back to search

CVE-2009-1979

Published: Oct 22, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTH_SESSKEY parameter length that leads to arbitrary code execution.

VendorProductVersions

n/a

n/a

affected
n/a

References

20091030 CVE-2009-1979 (Oracle RDBMS)
mailing-list
x_refsource_BUGTRAQ
37027
third-party-advisory
x_refsource_SECUNIA
1023057
vdb-entry
x_refsource_SECTRACK
TA09-294A
third-party-advisory
x_refsource_CERT
36747
vdb-entry
x_refsource_BID
59110
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now