CVE-2008-3999
published 2009-01-14CVE-2008-3999: Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 allows remote authenticated users to affect…
PriorityP417medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
1.99%
78.6th percentile
Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 allows remote authenticated users to affect availability, related to SYS.OLAPIMPL_T.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_10g | — | — |
| oracle | database_9i | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-3999 krb5 RPC library buffer overflow [Fdevel]
bugzilla·2007-11-01·CVSS 10.0
CVE-2007-3999 [CRITICAL] CVE-2007-3999 krb5 RPC library buffer overflow [Fdevel]
CVE-2007-3999 krb5 RPC library buffer overflow [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
What prevents you from doing an update? Do you need help? Otherwise please
prepare an update as soon as possible.
---
Fixed in nfs-utils-lib-1.1.1-2.fc9
---
Final Freeze is in effect now. Security fixes almost certainly warrant a freeze
break, so in case you build a fix for this, mail release engineering as
described here: [2]
[1] https://www.redhat.com/archives/fedora-devel-announce/2008-April/msg00007.html
[2] http://fedoraproject.org/wiki/ReleaseEngineering/FinalFreezePolicy
Thanks!
---
(In reply to comment #2)
> Fixed in nfs-utils-lib-1.1.1-2.fc9
Was that fixed upstream in
Bugzilla
CVE-2007-3999 krb5 RPC library buffer overflow [Fdevel]
bugzilla·2007-11-01·CVSS 10.0
CVE-2007-3999 [CRITICAL] CVE-2007-3999 krb5 RPC library buffer overflow [Fdevel]
CVE-2007-3999 krb5 RPC library buffer overflow [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
What prevents you from doing an update? Do you need help? Otherwise please
prepare an update as soon as possible.
---
Fixed in libtirpc-0.1.7-15.fc9.
---
libtirpc-0.1.7-15.fc8 has been pushed to the Fedora 8 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test the update, you can install it with
su -c 'yum --enablerepo=updates-testing update libtirpc'. You can provide feedback for this update here: http://admin.fedoraproject.org/F8/FEDORA-2008-1017
http://osvdb.org/51349http://secunia.com/advisories/33525http://www.oracle.com/technetwork/topics/security/cpujan2009-097901.htmlhttp://www.securityfocus.com/bid/33177http://www.securitytracker.com/id?1021561http://www.vupen.com/english/advisories/2009/0115http://osvdb.org/51349http://secunia.com/advisories/33525http://www.oracle.com/technetwork/topics/security/cpujan2009-097901.htmlhttp://www.securityfocus.com/bid/33177http://www.securitytracker.com/id?1021561http://www.vupen.com/english/advisories/2009/0115
2009-01-14
Published