CVE-2006-5336
published 2006-10-18CVE-2006-5336: Multiple unspecified vulnerabilities in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and have unknown impact and remote…
critical9CVSS 3.1
AVNACLAuSCCICAC
Multiple unspecified vulnerabilities in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and have unknown impact and remote authenticated attack vectors related to (1) sys.dbms_cdc_ipublish (Vuln# DB05) and (2) sys.dbms_cdc_isubscribe (DB06). NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB05 is for SQL injection in CREATE_CHANGE_TABLE and CHANGE_TABLE_TRIGGER, and DB06 is for PL/SQL injection in the PREPARE_UNBOUNDED_VIEW procedure.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/22396http://securitytracker.com/id?1017077http://www.databasesecurity.com/oracle/OracleOct2006-CPU-Analysis.pdfhttp://www.kb.cert.org/vuls/id/446100http://www.kb.cert.org/vuls/id/716964http://www.oracle.com/technetwork/topics/security/cpuoct2006-095368.htmlhttp://www.red-database-security.com/advisory/oracle_cpu_oct_2006.htmlhttp://www.securityfocus.com/archive/1/449110/100/0/threadedhttp://www.securityfocus.com/archive/1/449711/100/0/threadedhttp://www.securityfocus.com/bid/20588http://www.us-cert.gov/cas/techalerts/TA06-291A.htmlhttp://www.vupen.com/english/advisories/2006/4065http://secunia.com/advisories/22396http://securitytracker.com/id?1017077http://www.databasesecurity.com/oracle/OracleOct2006-CPU-Analysis.pdfhttp://www.kb.cert.org/vuls/id/446100http://www.kb.cert.org/vuls/id/716964http://www.oracle.com/technetwork/topics/security/cpuoct2006-095368.htmlhttp://www.red-database-security.com/advisory/oracle_cpu_oct_2006.htmlhttp://www.securityfocus.com/archive/1/449110/100/0/threadedhttp://www.securityfocus.com/archive/1/449711/100/0/threadedhttp://www.securityfocus.com/bid/20588http://www.us-cert.gov/cas/techalerts/TA06-291A.htmlhttp://www.vupen.com/english/advisories/2006/4065
2006-10-18
Published