Reported February 17, 2003, by NGSSoftware.

 

 

VERSIONS AFFECTED

 

  • Oracle9i Application Server

 

DESCRIPTION

 

A vulnerability in Oracle9i Application Server can result in remote compromise of the vulnerable server. This vulnerability stems from a flaw in the implementation of WebDAV on the server. By crafting a specially formed format string and sending it to the Web server, an attacker can overwrite addresses with arbitrary values, thereby granting the attacker control of the server. For more details about this vulnerability, see the discoverer’s web site.

 

VENDOR RESPONSE

 

Oracle has released an alert regarding this vulnerability.

 

CREDIT          

Discovered by NGSSoftware.