Oracle Text component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to CTXSYS.DRVDISP.
Oracle Database is prone to a buffer-overflow vulnerability that exists in Oracle Text.
The vulnerability can be exploited over the 'Oracle Net' protocol. For an exploit to succeed, the attacker must have 'Execute on CTXSYS.DRVDISP' privileges.
Successful exploits will allow attackers to execute arbitrary code in the context of the affected application. This may facilitate a complete system compromise.
Vendor Status:
Oracle has issued an update to correct this vulnerability