cbcvebase.
CVE-2009-1979
published 2009-10-22

CVE-2009-1979: Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality…

PriorityP275critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
76.36%
99.5th percentile
Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTH_SESSKEY parameter length that leads to arbitrary code execution.

Affected

2 ranges
VendorProductVersion rangeFixed in
oracledatabase_server
oracledatabase_server

Detection & IOCsextracted from sources · hover to see the quote

port1521
commandAUTH_SESSKEY (oversized/malformed value sent in OAUTH TNS packet to trigger stack buffer overflow)
otherRet=0x01347468 (p/p/r in oracle.exe v10.2.0.3, Oracle 10.2.0.4.0 EE)
otherRet=0x011b0528 (p/p/r in oracle.exe v10.2.0.3, Oracle 10.2.0.1.0 EE)
bytes
05 26 00 00 06 00 00 00 00 00 03 73 03 FE FF FF FF 05 00 00 00 01 01 00 00 ... AUTH_SESSKEY overflow OAUTH packet header
  • The exploit targets Oracle 10.2.0.1.0 and 10.2.0.4.0 Enterprise Edition on 32-bit Windows. Version detection via TNS COMMAND=VERSION can be used to identify vulnerable hosts; the Metasploit module checks for the string '32-bit Windows: Version 10.2.0.1.0' or '32-bit Windows: Version 10.2.0.4.0' in the version reply.
  • ·The Metasploit module's automatic target detection relies on the TNS VERSION command response being accessible. If the Oracle listener is configured to reject VERSION queries or is behind a firewall filtering TNS, automatic detection will fail.
  • ·The Oracle 10.2.0.1.0 target (Ret=0x011b0528) is listed as 'Untested' in the Metasploit module; only Oracle 10.2.0.4.0 Enterprise Edition on 32-bit Windows was confirmed exploitable.
  • ·The vulnerability affects Oracle Database Network Authentication component on versions 10.1.0.5 and 10.2.0.4; the exact attack vector details remain officially unspecified by Oracle, with the AUTH_SESSKEY overflow being attributed to independent researcher analysis rather than Oracle's own advisory.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.