CNCVE编号:CNCVE-20000818 CVE编号:CVE-2000-0818 安全级别:高 漏洞中文描述: Oracle listener 监听器程序7.3.4、8.0.6以及8.1.6的默认安装程序中存在缓冲区溢出漏洞,该漏洞导致攻击者可以通过SET TRC_FILE或SET LOG_FILE命令使日志信息附加到任意文件后并执行命令。 漏洞英文描述: The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands. 漏洞参考: ISS:20001025 Vulnerability in the Oracle Listener Program | URL:http://xforce.iss.net/alerts/advise66.php | CONFIRM:http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误