Oracle Security Component sys.pbsde buffer overflow
Added: 11/07/2006CVE: CVE-2005-3438
BID: 15134
OSVDB: 20612
Background
pbsde is a package of stored procedures which is part of the base installation of Oracle Database.Problem
A buffer overflow in the sys.pbsde.init procedure allows database users to execute arbitrary commands.Resolution
Apply the patch referenced in the October 2005 Critical Patch Update.References
http://www.us-cert.gov/cas/techalerts/TA05-292A.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2005-10/0430.html
Limitations
Exploit works on Oracle Database 10g 10.1.0.2 and requires the login and password of a valid database account.Platforms
WindowsBack to exploit index