Oracle XML Component DBMS_XMLSCHEMA.GENERATESCHEMA buffer overflow
Added: 11/03/2006CVE: CVE-2006-0272
BID: 16287
OSVDB: 22567
Background
Oracle Database Server includes the DBMS_XMLSCHEMA component, which contains procedures for managing XML schemas.Problem
A buffer overflow vulnerability in the DBMS_XMLSCHEMA.GENERATESCHEMA procedure allows database users to execute arbitrary commands.Resolution
Install the patch referenced in the January 2006 Critical Patch Update.References
http://www.kb.cert.org/vuls/id/545804http://archives.neohapsis.com/archives/vulnwatch/2006-q1/0037.html
Limitations
Exploit works on Oracle Database 10.1.0.2 and 9.2.0.1 and requires the login and password to an Oracle account with connect privileges.Platforms
WindowsBack to exploit index