Oracle Net Listener Format String Vulnerability
BID:5460
Info
Oracle Net Listener Format String Vulnerability
| Bugtraq ID: | 5460 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2002 12:00AM |
| Updated: | Aug 14 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to David Lichfield of NGSSoftware Insight Security Research. |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.2 .0.2 Oracle Oracle9i Standard Edition 9.2 .0.1 Oracle Oracle9i Standard Edition 9.0.2 Oracle Oracle9i Standard Edition 9.0.1 .3 Oracle Oracle9i Standard Edition 9.0.1 .2 Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 9.0 Oracle Oracle8i Standard Edition 8.1.7 .4 Oracle Oracle8i Standard Edition 8.1.7 .1 Oracle Oracle8i Standard Edition 8.1.7 Oracle Oracle8i Standard Edition 8.1.6 Oracle Oracle8i Standard Edition 8.1.5 Oracle Oracle7 7.3.4 |
| Not Vulnerable: | |
Discussion
Oracle Net Listener Format String Vulnerability
A vulnerability has been reported for the Listener Control utility (LSNRCTL). Reportedly, the Listener Control utility is vulnerable to format string attacks. This vulnerability is due to the default configuration of the Oracle Listener. The Listener, by default, allows users to modify configuration files without authenticating. It is possible for an attacker to modify certain entries in the file, listener.ora, to insert a format string exploit.
An attacker exploiting this vulnerability may obtain control over the Listener Control utility.
A vulnerability has been reported for the Listener Control utility (LSNRCTL). Reportedly, the Listener Control utility is vulnerable to format string attacks. This vulnerability is due to the default configuration of the Oracle Listener. The Listener, by default, allows users to modify configuration files without authenticating. It is possible for an attacker to modify certain entries in the file, listener.ora, to insert a format string exploit.
An attacker exploiting this vulnerability may obtain control over the Listener Control utility.
Exploit / POC
Oracle Net Listener Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Oracle Net Listener Format String Vulnerability
Solution:
A patch is available. Oracle customers are advised to reference Bug Number 2395416 on Oracle Metalink:
http://metalink.oracle.com
Solution:
A patch is available. Oracle customers are advised to reference Bug Number 2395416 on Oracle Metalink:
http://metalink.oracle.com
References
Oracle Net Listener Format String Vulnerability
References:
References:
- Oracle Security Alert #40 (pdf) (Oracle)