GCVE-VVD-CERTCC-2000-118277
Advisory Published
Vulnetix · Advisory published October 18, 2000
Oracle Internet Directory version 2.0.6, which ships with Oracle version 8i for Linux (8.1.6), contains a program, oidldapd, that is an LDAP Daemon. There is a buffer overflow in the LDAP Daemon that allows a local user to obtain the euid of the oidldapd process, typically user oracle.