CVE-2007-1442

Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACLs), which allows local users to gain privileges.
Configurations

Configuration 1

cpe:2.3:a:oracle:database_server:10.2.2:*:standard:*:*:*:*:*
cpe:2.3:a:oracle:database_server:10.2.2:*:personal:*:*:*:*:*
cpe:2.3:a:oracle:database_server:10.2.3:*:personal:*:*:*:*:*
cpe:2.3:a:oracle:database_server:10.2.3:*:standard:*:*:*:*:*
cpe:2.3:a:oracle:database_server:10.2.2:*:enterprise:*:*:*:*:*
cpe:2.3:a:oracle:database_server:10.2.1:*:enterprise:*:*:*:*:*
cpe:2.3:a:oracle:database_server:10.2.1:*:personal:*:*:*:*:*
cpe:2.3:a:oracle:database_server:10.2.3:*:enterprise:*:*:*:*:*
cpe:2.3:a:oracle:database_server:10.2.1:*:standard:*:*:*:*:*

Information

Published : 2007-03-14 12:19

Updated : 2008-11-15 06:44


NVD link : CVE-2007-1442

Mitre link : CVE-2007-1442

Products Affected
No products.