Oracle Database Multiple Unspecified Vulnerabilities
BID:12296
Info
Oracle Database Multiple Unspecified Vulnerabilities
| Bugtraq ID: | 12296 |
| Class: | Unknown |
| CVE: |
CVE-2004-0200 CVE-2005-0297 CVE-2005-0298 CVE-2005-0701 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Discovery of these vulnerabilities is credited to NGSSoftware. |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.2 .3 Oracle Oracle9i Standard Edition 9.2 .0.5 Oracle Oracle9i Standard Edition 9.2 .0.3 Oracle Oracle9i Standard Edition 9.2 .0.2 Oracle Oracle9i Standard Edition 9.2 .0.1 Oracle Oracle9i Standard Edition 9.2 Oracle Oracle9i Standard Edition 9.0.2 Oracle Oracle9i Standard Edition 9.0.1 .5 Oracle Oracle9i Standard Edition 9.0.1 .4 Oracle Oracle9i Standard Edition 9.0.1 .3 Oracle Oracle9i Standard Edition 9.0.1 .2 Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 9.0 .2.4 Oracle Oracle9i Standard Edition 9.0 Oracle Oracle9i Standard Edition 8.1.7 Oracle Oracle9i Personal Edition 9.2 .0.5 Oracle Oracle9i Personal Edition 9.2 .0.3 Oracle Oracle9i Personal Edition 9.2 .0.2 Oracle Oracle9i Personal Edition 9.2 .0.1 Oracle Oracle9i Personal Edition 9.2 Oracle Oracle9i Personal Edition 9.0.1 .5 Oracle Oracle9i Personal Edition 9.0.1 .4 Oracle Oracle9i Personal Edition 9.0.1 Oracle Oracle9i Personal Edition 9.0 .2.4 Oracle Oracle9i Personal Edition 8.1.7 Oracle Oracle9i Lite 5.0 .2.9.0 Oracle Oracle9i Lite 5.0 .2.0.0 Oracle Oracle9i Lite 5.0 .1.0.0 Oracle Oracle9i Lite 5.0 .0.0.0 Oracle Oracle9i Enterprise Edition 9.2 .2 Oracle Oracle9i Enterprise Edition 9.2 .0.5 Oracle Oracle9i Enterprise Edition 9.2 .0.3 Oracle Oracle9i Enterprise Edition 9.2 .0.1 Oracle Oracle9i Enterprise Edition 9.2 .0 Oracle Oracle9i Enterprise Edition 9.0.1 .5 Oracle Oracle9i Enterprise Edition 9.0.1 .4 Oracle Oracle9i Enterprise Edition 9.0.1 Oracle Oracle9i Enterprise Edition 9.0 .2.4 Oracle Oracle9i Enterprise Edition 8.1.7 Oracle Oracle9i Developer Edition 9.0.4 Oracle Oracle9i Client Edition 9.2 .0.2 Oracle Oracle9i Client Edition 9.2 .0.1 Oracle Oracle9i Application Server 9.0.3 .1 Oracle Oracle9i Application Server 9.0.3 Oracle Oracle9i Application Server 9.0.2 .3 Oracle Oracle9i Application Server 9.0.2 .2 Oracle Oracle9i Application Server 9.0.2 .1 Oracle Oracle9i Application Server 9.0.2 .0.1 Oracle Oracle9i Application Server 9.0.2 .0.0 Oracle Oracle9i Application Server 9.0.2 Oracle Oracle9i Application Server 1.0.2 .2.2 Oracle Oracle9i Application Server 1.0.2 .2 Oracle Oracle9i Application Server 1.0.2 .1s Oracle Oracle9i Application Server 1.0.2 Oracle Oracle9i Application Server Oracle Oracle10g Standard Edition 10.1 .0.2 Oracle Oracle10g Standard Edition 9.0.4 .0 Oracle Oracle10g Personal Edition 10.1 .0.2 Oracle Oracle10g Personal Edition 9.0.4 .0 Oracle Oracle10g Enterprise Edition 10.1 .0.2 Oracle Oracle10g Enterprise Edition 9.0.4 .0 Oracle Oracle10g Application Server 10.1 .0.2 Oracle Oracle10g Application Server 9.0.4 .0 |
| Not Vulnerable: | |
Discussion
Oracle Database Multiple Unspecified Vulnerabilities
It is reported that Oracle Database 10g and Oracle9i Database Server products contain multiple unspecified vulnerabilities.
The reported vulnerabilities include SQL injection vulnerabilities and a buffer overflow issue.
It is reported that the issues may be exploited by unprivileged users to gain DBA privileges or to execute arbitrary attacker-supplied code in the context of the affected database service.
NGSSoftware has stated that further details will be released on 18th of April 2005 regarding the issues that are described in this BID. Please see the referenced message for more information.
It is reported that Oracle Database 10g and Oracle9i Database Server products contain multiple unspecified vulnerabilities.
The reported vulnerabilities include SQL injection vulnerabilities and a buffer overflow issue.
It is reported that the issues may be exploited by unprivileged users to gain DBA privileges or to execute arbitrary attacker-supplied code in the context of the affected database service.
NGSSoftware has stated that further details will be released on 18th of April 2005 regarding the issues that are described in this BID. Please see the referenced message for more information.
Exploit / POC
Oracle Database Multiple Unspecified Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Oracle Database Multiple Unspecified Vulnerabilities
Solution:
Oracle has released a Critical Patch Update to address various issues. Information regarding obtaining and applying an appropriate patch can be found in the Oracle Critical Patch Update in references.
Information about Oracle Database Patch Availability can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=293737.1
Information about Application Server Patch Availability can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=293738.1
Information about Oracle Collaboration Suite Patch Availability can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=293740.1
Information about Oracle E-Business Patch Availability can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=293741.1
Please contact the vendor for more information.
Solution:
Oracle has released a Critical Patch Update to address various issues. Information regarding obtaining and applying an appropriate patch can be found in the Oracle Critical Patch Update in references.
Information about Oracle Database Patch Availability can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=293737.1
Information about Application Server Patch Availability can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=293738.1
Information about Oracle Collaboration Suite Patch Availability can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=293740.1
Information about Oracle E-Business Patch Availability can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=293741.1
Please contact the vendor for more information.
References
Oracle Database Multiple Unspecified Vulnerabilities
References:
References:
- Critical Patch Update - January 2005 (Oracle)
- Oracle Homepage (Oracle)
- Oracle Support Metalink (Oracle)
- Oracle Support Page (Oracle)