CNCVE编号:CNCVE-20020078 CVE编号: 安全级别:中 漏洞中文描述: Oracle 9i 的tnslsnr.exe是TNSListener的守护进程,dbsnmp_start和dbsnmp_stop是LSNRCTL下的二个命令,在正常情况下,这二个程序是只能在本地执行的,但是如果通过恶意程序远程发送(CONNECT_DATA=(COMMAND=dbsnmp_start)),当远程的tnslsnr.ex接收到该命令,就会发生内存读取错误,如果配合tnslsnr.exe的其他漏洞,可以获取system权限。 漏洞英文描述: tnslsnr.exe is the daemon of TNSListener in Oracle 9i, dbsnmp_start and dbsnmp_stop are two commands of LSNRCTL,in a normal condition,these two programs must be excuted in local host,but if it is sent by a malice program remotely(CONNECT_DATA=(COMMAND=dbsnmp_start)),it will cause memory read error,when remote tnslsnr.exe receives this command.if it follows other vulnerability of tnslsnr.exe,may cause attackers gain system access. 漏洞参考: 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误