E-Mail:
Author Avatar

Oracle9i Database Multiple Buffer Overflow Vulnerabilities

This is the software that Oracle touted as being unbreakable.

Critical: Moderately critical
Impact: Privilege escalation, System access
Where: From local network
Software: Oracle9i Database Enterprise Edition, Oracle9i Database Standard Edition

Description:
Cesar Cerrudo and Mark Litchfield have discovered multiple vulnerabilities in Oracle9i Database, which can be exploited by malicious database users to compromise the system and gain escalated privileges.

The first vulnerabilities are caused due to boundary errors in two functions used for interval conversion (”NUMTOYMINTERVAL” and “NUMTODSINTERVAL”). These can be exploited to cause buffer overflows by supplying an overly long “char_expr” string. These two vulnerabilities have been reported in versions prior to 9.2.0.4 (Patchset 3).

The last two vulnerabilities are caused due to boundary errors in the “FROM_TZ” function and in the “TIME_ZONE” parameter.

Both vulnerabilities reportedly affect versions prior to 9.2.0.3.

Successful exploitation of the vulnerabilities may allow a malicious, unprivileged database user to execute arbitrary code with either SYSTEM or ORACLE privileges.

Solution:
Update to version 9.2.0.4 and apply Patch 3, which reportedly is available via the Metalink site:
http://metalink.oracle.com/

What Do You Think?

 


Anti-Spam Image

Want to Start a Blog Here for Free?

Are you an expert in one subject or another? If your goal is to help others and dispense hard-earned information back to the community, stake a claim on your very own Lockergnome blog today! You can write about anything - no matter the topic. Sign-up to start blogging!