CVE-2023-34364 is a critical buffer overflow vulnerability affecting Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An attacker can exploit this by providing an overly large value in a connection string, leading to arbitrary code execution on the affected host. With a CVSS score of 9.8 (CRITICAL), this vulnerability has a network-based attack vector, low attack complexity, and results in complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating awareness and potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 08.02.2770CPE matchmatch criteria | cpe:2.3:a:progress:datadirect_odbc_oracle_wire_protocol_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.