Oracle 8i TNS Listener Buffer Overflow Vulnerability
BID:2941
Info
Oracle 8i TNS Listener Buffer Overflow Vulnerability
| Bugtraq ID: | 2941 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-0499 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2001 12:00AM |
| Updated: | Mar 19 2015 08:05AM |
| Credit: | Discovered by Nishad Herath and Brock Tellier of COVERT Labs at Network Associates. |
| Vulnerable: |
Oracle Oracle8i Standard Edition 8.1.7 Oracle Oracle8i Standard Edition 8.1.6 Oracle Oracle8i Standard Edition 8.1.5 |
| Not Vulnerable: |
Oracle Oracle9i Standard Edition 9.0.2 Oracle Oracle9i Standard Edition 9.0.1 .3 Oracle Oracle9i Standard Edition 9.0.1 .2 Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 9.0 |
Discussion
Oracle 8i TNS Listener Buffer Overflow Vulnerability
Oracle 8i ships with a component called TNS Listener. TNS Listener is used to arbitrate communication between remote database clients/applications and the database server.
There exists a remotely exploitable buffer overflow in TNS Listener. Remote attackers can execute arbitrary code on affected hosts. This vulnerability does not require authentication to exploit.
On Windows 2000/NT4 systems, TNS Listener runs with 'LocalSystem' privileges. These are equivelent to administrative and any attacker to exploit this vulnerability on such a system would gain control over it.
On Unix systems, Oracle processes such as the listener typically run as their own userid. Exploitation of this vulnerability on these systems would provide an attacker with local access to the victim host. It is significantly easier for attackers to compromise the entire system with local access.
Note: Versions 8.1.5, 8.1.6, and 8.1.7 are confirmed as being vulnerable. Previous versions are likely vulnerable as well.
Oracle 8i ships with a component called TNS Listener. TNS Listener is used to arbitrate communication between remote database clients/applications and the database server.
There exists a remotely exploitable buffer overflow in TNS Listener. Remote attackers can execute arbitrary code on affected hosts. This vulnerability does not require authentication to exploit.
On Windows 2000/NT4 systems, TNS Listener runs with 'LocalSystem' privileges. These are equivelent to administrative and any attacker to exploit this vulnerability on such a system would gain control over it.
On Unix systems, Oracle processes such as the listener typically run as their own userid. Exploitation of this vulnerability on these systems would provide an attacker with local access to the victim host. It is significantly easier for attackers to compromise the entire system with local access.
Note: Versions 8.1.5, 8.1.6, and 8.1.7 are confirmed as being vulnerable. Previous versions are likely vulnerable as well.
Exploit / POC
Oracle 8i TNS Listener Buffer Overflow Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploit code by benjurry <[email protected]> has been published:
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploit code by benjurry <[email protected]> has been published:
Solution / Fix
Oracle 8i TNS Listener Buffer Overflow Vulnerability
Solution:
Oracle has stated that this vulnerability is not present in the Oracle 9i database server. As of 11/2002, It is not clear if patches are yet available for Oracle 8 systems. Administrators are advised to completely block external access to the listener until Oracle support can be contacted or systems can be upgraded. See: http://otn.oracle.com/deploy/security/pdf/nai_net8_bof.pdf
Please visit the Metalink website for patches and more information.
http://metalink.oracle.com
Solution:
Oracle has stated that this vulnerability is not present in the Oracle 9i database server. As of 11/2002, It is not clear if patches are yet available for Oracle 8 systems. Administrators are advised to completely block external access to the listener until Oracle support can be contacted or systems can be upgraded. See: http://otn.oracle.com/deploy/security/pdf/nai_net8_bof.pdf
Please visit the Metalink website for patches and more information.
http://metalink.oracle.com
References
Oracle 8i TNS Listener Buffer Overflow Vulnerability
References:
References:
- Buffer Overflow in the Oracle8i Listener (Oracle)
- Oracle Support Metalink (Oracle)
- Oracle Support Page (Oracle)
- OracleDB TNS commands overflow exploit (CORE Security)