Oracle Startup Script LD_LIBRARY_PATH Vulnerability
BID:6414
Info
Oracle Startup Script LD_LIBRARY_PATH Vulnerability
| Bugtraq ID: | 6414 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 17 2002 12:00AM |
| Updated: | Dec 17 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to [email protected]. |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.0.2 Oracle Oracle9i Standard Edition 9.0.1 .3 Oracle Oracle9i Standard Edition 9.0.1 .2 Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 9.0 |
| Not Vulnerable: | |
Discussion
Oracle Startup Script LD_LIBRARY_PATH Vulnerability
A problem with the Oracle startup script could lead to arbitrary library attacks. The problem is in the initialization of the LD_LIBRARY_PATH environment variable.
The 'oracle.sh' script insecurely initializes the LD_LIBRARY_PATH environment variable. Specifically, the script does not properly check whether the environment variable already exists and creates an LD_LIBRARY_PATH with an empty element. When ld is used, it will look for paths to search for in the LD_LIBRARY_PATH environment variable.
An attacker can exploit this vulnerability to trick a user into performing some actions in a directory where a malicious library exists. This may allow an attacker to run arbitary code, contained within the malicious library, with the privileges of the victim user.
A problem with the Oracle startup script could lead to arbitrary library attacks. The problem is in the initialization of the LD_LIBRARY_PATH environment variable.
The 'oracle.sh' script insecurely initializes the LD_LIBRARY_PATH environment variable. Specifically, the script does not properly check whether the environment variable already exists and creates an LD_LIBRARY_PATH with an empty element. When ld is used, it will look for paths to search for in the LD_LIBRARY_PATH environment variable.
An attacker can exploit this vulnerability to trick a user into performing some actions in a directory where a malicious library exists. This may allow an attacker to run arbitary code, contained within the malicious library, with the privileges of the victim user.
Exploit / POC
Oracle Startup Script LD_LIBRARY_PATH Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Oracle Startup Script LD_LIBRARY_PATH Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Oracle Startup Script LD_LIBRARY_PATH Vulnerability
References:
References: