Oracle 8i TNS Listener Local Command Parameter Buffer Overflow Vulnerability
BID:4413
Info
Oracle 8i TNS Listener Local Command Parameter Buffer Overflow Vulnerability
| Bugtraq ID: | 4413 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 01 2002 12:00AM |
| Updated: | Apr 01 2002 12:00AM |
| Credit: | Discovered by KF <[email protected]>. |
| Vulnerable: |
Oracle Oracle8i Standard Edition 8.1.5 |
| Not Vulnerable: | |
Discussion
Oracle 8i TNS Listener Local Command Parameter Buffer Overflow Vulnerability
Oracle 8i is a powerful relational database product. It is available for Windows, Linux, and a wide range of Unix operating systems.
A vulnerability has been reported with some versions of Oracle 8i for Linux. A local attacker able to execute the tnslsnr process may pass an oversized command line parameter and cause a buffer overflow, possibly leading to the execution of arbitrary code as the user 'oracle'.
Versions of Oracle 8i available for other operating systems have not yet been confirmed as vulnerable.
Oracle 8i is a powerful relational database product. It is available for Windows, Linux, and a wide range of Unix operating systems.
A vulnerability has been reported with some versions of Oracle 8i for Linux. A local attacker able to execute the tnslsnr process may pass an oversized command line parameter and cause a buffer overflow, possibly leading to the execution of arbitrary code as the user 'oracle'.
Versions of Oracle 8i available for other operating systems have not yet been confirmed as vulnerable.
Exploit / POC
Oracle 8i TNS Listener Local Command Parameter Buffer Overflow Vulnerability
An exploit has been provided by The Itch / Promisc (http://www.promisc.org):
An exploit has been provided by The Itch / Promisc (http://www.promisc.org):
Solution / Fix
Oracle 8i TNS Listener Local Command Parameter Buffer Overflow Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Oracle 8i TNS Listener Local Command Parameter Buffer Overflow Vulnerability
References:
References:
- Oracle Homepage (Oracle)