HIGH
Unspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB29
Published Jan 18, 2006
9.0
HIGHCVSS 2.0
EPSS 5.82%
Description
Unspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB29. NOTE: based on mutual credits by the relevant sources, it is highly likely that this issue is a buffer overflow in the (a) DBMS_XMLSCHEMA and (b) DBMS_XMLSCHEMA_INT packages, as exploitable via long arguments to (1) XDB.DBMS_XMLSCHEMA.GENERATESCHEMA or (2) XDB.DBMS_XMLSCHEMA.GENERATESCHEMAS.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (16)
- http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0893.html mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/18493 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18608 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1015499 vdb-entryx_refsource_SECTRACK
- http://www.argeniss.com/research/ARGENISS-ADV-010601.txt x_refsource_MISC
- http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf x_refsource_MISC
- http://www.kb.cert.org/vuls/id/545804 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.kb.cert.org/vuls/id/891644 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html x_refsource_CONFIRM
- http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html x_refsource_MISC
- http://www.securityfocus.com/bid/16287 vdb-entryx_refsource_BID
- http://www.us-cert.gov/cas/techalerts/TA06-018A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2006/0243 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/0323 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24321 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24376 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 18, 2006
Updated Aug 7, 2024
Reserved Jan 18, 2006
Link CVE-2006-0272
CISA Vulnrichment
Updated n/a