Oracle TNS Listener Arbitrary Library Call Execution Vulnerability
BID:4033
Info
Oracle TNS Listener Arbitrary Library Call Execution Vulnerability
| Bugtraq ID: | 4033 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2002 12:00AM |
| Updated: | Feb 06 2002 12:00AM |
| Credit: | Discovered by David Litchfield ([email protected]) of Next Generation Security Software. |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 9.0 Oracle Oracle8i Standard Edition 8.1.7 .4 Oracle Oracle8i Standard Edition 8.1.7 .1 Oracle Oracle8i Standard Edition 8.1.7 .0.0 Oracle Oracle8i Standard Edition 8.1.7 Oracle Oracle8i Standard Edition 8.1.6 Oracle Oracle8i Standard Edition 8.1.5 Oracle Oracle8i Enterprise Edition 8.1.7 .4.0 Oracle Oracle8i Enterprise Edition 8.1.7 .1.0 Oracle Oracle8i Enterprise Edition 8.1.7 .0.0 Oracle Oracle8i Enterprise Edition 8.1.6 .1.0 Oracle Oracle8i Enterprise Edition 8.1.6 .0.0 Oracle Oracle8i Enterprise Edition 8.1.5 .1.0 Oracle Oracle8i Enterprise Edition 8.1.5 .0.2 Oracle Oracle8i Enterprise Edition 8.1.5 .0.0 Oracle Oracle8i Enterprise Edition 8.0.6 .0.1 Oracle Oracle8i Enterprise Edition 8.0.6 .0.0 Oracle Oracle8i Enterprise Edition 8.0.5 .0.0 Oracle Oracle8 8.1.7 .4 Oracle Oracle8 8.1.7 Oracle Oracle8 8.1.6 Oracle Oracle8 8.1.5 Oracle Oracle8 8.0.6 Oracle Oracle8 8.0.5 .1 Oracle Oracle8 8.0.5 Oracle Oracle8 8.0.4 Oracle Oracle8 8.0.3 Oracle Oracle8 8.0.2 Oracle Oracle8 8.0.1 |
| Not Vulnerable: | |
Discussion
Oracle TNS Listener Arbitrary Library Call Execution Vulnerability
Oracle is a commercial relational database product. Oracle is available for the Unix, Linux, and Microsoft Windows platforms.
Oracle allows PL/SQL code to execute arbitrary library calls through a request to the Oracle Listener process. As there is no authentication, any party able to connect to the Listener may emulate this conversation and cause arbitrary library calls to be executed as the oracle user, including system and exec. It is also possible to redirect standard IO to a socket. This may immediately lead to a local compromise of the Oracle user.
On Windows based systems, the call is run within the local SYSTEM security context. On Unix systems, the Listener may run with user-level privileges.
** A reliable source has indicated that a patch for this issue is available to Oracle customers but introduces the issue described in BID 8267 as a side effect. Symantec has not been able to confirm this information.
Oracle is a commercial relational database product. Oracle is available for the Unix, Linux, and Microsoft Windows platforms.
Oracle allows PL/SQL code to execute arbitrary library calls through a request to the Oracle Listener process. As there is no authentication, any party able to connect to the Listener may emulate this conversation and cause arbitrary library calls to be executed as the oracle user, including system and exec. It is also possible to redirect standard IO to a socket. This may immediately lead to a local compromise of the Oracle user.
On Windows based systems, the call is run within the local SYSTEM security context. On Unix systems, the Listener may run with user-level privileges.
** A reliable source has indicated that a patch for this issue is available to Oracle customers but introduces the issue described in BID 8267 as a side effect. Symantec has not been able to confirm this information.
Exploit / POC
Oracle TNS Listener Arbitrary Library Call Execution Vulnerability
The discoverer of this vulnerability has reportedly developed a working exploit that is not publically available or known to be circulating in the wild.
The discoverer of this vulnerability has reportedly developed a working exploit that is not publically available or known to be circulating in the wild.
Solution / Fix
Oracle TNS Listener Arbitrary Library Call Execution Vulnerability
Solution:
Oracle has released Security Alert #57 to address this issue. Please see the referenced advisory for further information. Oracle states in their alert that versions 9.0.1.4, 8.1.7.4, 8.1.6.x, 8.0.6.3, 8.0.5.x, 7.3.x, and other versions.
David Litchfield <[email protected]> has confirmed that Oracle version 8.1.7.4 is still vulnerable to this issue.
Solution:
Oracle has released Security Alert #57 to address this issue. Please see the referenced advisory for further information. Oracle states in their alert that versions 9.0.1.4, 8.1.7.4, 8.1.6.x, 8.0.6.3, 8.0.5.x, 7.3.x, and other versions.
David Litchfield <[email protected]> has confirmed that Oracle version 8.1.7.4 is still vulnerable to this issue.
References
Oracle TNS Listener Arbitrary Library Call Execution Vulnerability
References:
References:
- Oracle Homepage (Oracle)
- Oracle Security Alert #29 (Oracle)
- Oracle Security Alert #57 (Oracle)
- Oracle Support Metalink (Oracle)
- Oracle Support Page (Oracle)
- Re: question about oracle advisory ("David Litchfield"
) - Three years and ten months without a patch ("David Litchfield"
)