CVE-2011-2238
published 2011-07-20CVE-2011-2238: Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote…
PriorityP417medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.30%
67.5th percentile
Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect integrity, related to DBMS_SYS_SQL.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x583-m9v2-5288: Unspecified vulnerability in the Database Vault component in Oracle Database Server 10
ghsa_unreviewed·2022-05-17
CVE-2011-2238 [MEDIUM] GHSA-x583-m9v2-5288: Unspecified vulnerability in the Database Vault component in Oracle Database Server 10
Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect integrity, related to DBMS_SYS_SQL.
Red Hat
libvirt: regression introduced in disk probe logic
vendor_redhat·2011-05-31·CVSS 4.4
CVE-2011-2178 [MEDIUM] libvirt: regression introduced in disk probe logic
libvirt: regression introduced in disk probe logic
The virSecurityManagerGetPrivateData function in security/security_manager.c in libvirt 0.8.8 through 0.9.1 uses the wrong argument for a sizeof call, which causes incorrect processing of "security manager private data" that "reopens disk probing" and might allow guest OS users to read arbitrary files on the host OS. NOTE: this vulnerability exists because of a CVE-2010-2238 regression.
Statement: Not vulnerable. This issue did not affect the version of libvirt as shipped with Red Hat Enterprise Linux 5 and 6 as we did not backport upstream commit d6623003.
Package: libvirt (Red Hat Enterprise Linux 6) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2178 libvirt: regression introduced in disk probe logic
bugzilla·2011-06-01·CVSS 4.4
CVE-2011-2178 [MEDIUM] CVE-2011-2178 libvirt: regression introduced in disk probe logic
CVE-2011-2178 libvirt: regression introduced in disk probe logic
Regression introduced in commit d6623003 (v0.8.8) - using the wrong sizeof operand meant that security manager private data was overlaying the allowDiskFOrmatProbing member of struct _virSecurityManager. This reopens disk probing, which was supposed to be prevented by the solution to CVE-2010-2238.
Upstream patch:
https://www.redhat.com/archives/libvir-list/2011-May/msg01935.html
Discussion:
Created libvirt tracking bugs for this issue
Affects: fedora-15 [bug 709775]
Affects: fedora-rawhide [bug 709777]
---
Statement:
Not vulnerable. This issue did not affect the version of libvirt as shipped with Red Hat Enterprise Linux 5 and 6 as we did not backport upstream commit d6623003.
---
verify pass on
kernel-2.6.32-156.e
Bugzilla
CVE-2011-2178 libvirt: regression introduced in disk probe logic [fedora-15]
bugzilla·2011-06-01·CVSS 4.4
CVE-2011-2178 [MEDIUM] CVE-2011-2178 libvirt: regression introduced in disk probe logic [fedora-15]
CVE-2011-2178 libvirt: regression introduced in disk probe logic [fedora-15]
fedora-15 tracking bug for libvirt: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
This upstream commit needs to be backported to F15:
commit b598ac555c8fe67ffc39ac8ef25fe7e6b28ae3f2
Author: Eric Blake
Date: Thu May 26 08:18:46 2011 -0600
security: plug regression introduced in disk probe logic
wrong sizeof operand meant that security manager private data
was overlaying the allowDiskFormatProbing member of struct
_virSecurityManager. This reopens disk probing, which was
supposed to be prevented by the solution to CVE-2010-2238.
* src
2011-07-20
Published