Vulnerability record · CVE-2002-0965 · published 4 October 2002
CVE-2002-0965: Oracle TNS Listener SERVICE_NAME buffer overflow on Windows
Oracle · Oracle9i
The TNS Listener in Oracle 9i Database Server on Windows (and Oracle 8 on VM) mishandles a long SERVICE_NAME parameter when writing an error message to a log file, causing a buffer overflow. A local user can trigger the overflow and execute arbitrary code in the listener's context. The flaw matters because the listener is a core database component and the record provides no affected version detail beyond the product names.
Description
Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a log file.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityHigh CVSS 2.0 score and very high EPSS probability, but no confirmed exploitation and an old, narrowly scoped product set.
What it is
The TNS Listener in Oracle 9i Database Server on Windows (and Oracle 8 on VM) mishandles a long SERVICE_NAME parameter when writing an error message to a log file, causing a buffer overflow. A local user can trigger the overflow and execute arbitrary code in the listener's context. The flaw matters because the listener is a core database component and the record provides no affected version detail beyond the product names.
Impact
An attacker gains arbitrary code execution with the privileges of the TNS Listener process, which can lead to full compromise of the database host. The record does not state whether privilege escalation beyond the listener account is possible.
Attack surface
Reached through the TNS Listener service on Windows systems, per the description, via a crafted SERVICE_NAME parameter. The description says local users, while the CVSS 2.0 vector is AV:N/Au:N, so the record is internally inconsistent on whether network access and authentication are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded; EPSS is high at 0.6981 (99.3rd percentile), but the references carry no exploit tags, so active exploitation is not confirmed by this record.
What to do
- Apply the Oracle patch referenced in the vendor advisory (net9_dos_alert.pdf) and SecurityFocus BID 4845.
- Restrict network access to the TNS Listener port to trusted hosts only.
- Run the listener with the least privileges possible and avoid unnecessary local accounts on database hosts.
- Monitor and rotate listener log files, and validate that SERVICE_NAME input is not logged unsafely after patching.
Detection
- Inspect TNS Listener log files for unusually long or malformed SERVICE_NAME entries and error-message write failures.
- Monitor for listener process crashes or restarts on Windows database hosts.
- Alert on unexpected child processes or code execution originating from the listener process.
- Review network connections to the listener port from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0096.html | |
| http://online.securityfocus.com/archive/1/276526 | |
| http://otn.oracle.com/deploy/security/pdf/net9_dos_alert.pdf | PatchVendor Advisory |
| http://www.iss.net/security_center/static/9288.php | |
| http://www.kb.cert.org/vuls/id/630091 | US Government Resource |
| http://www.securityfocus.com/bid/4845 | PatchVendor Advisory |
| http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0096.html | |
| http://online.securityfocus.com/archive/1/276526 | |
| http://otn.oracle.com/deploy/security/pdf/net9_dos_alert.pdf | PatchVendor Advisory |
| http://www.iss.net/security_center/static/9288.php | |
| http://www.kb.cert.org/vuls/id/630091 | US Government Resource |
| http://www.securityfocus.com/bid/4845 | PatchVendor Advisory |
Track CVE-2002-0965 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0965), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.