Oracle Database Server ORACLE.EXE Buffer Overflow Vulnerability
BID:6849
Info
Oracle Database Server ORACLE.EXE Buffer Overflow Vulnerability
| Bugtraq ID: | 6849 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2003 12:00AM |
| Updated: | Feb 11 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Mark Litchfield. |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.2 .0.2 Oracle Oracle9i Standard Edition 9.2 .0.1 Oracle Oracle9i Standard Edition 9.0.2 Oracle Oracle9i Standard Edition 9.0.1 .3 Oracle Oracle9i Standard Edition 9.0.1 .2 Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 9.0 Oracle Oracle8i Standard Edition 8.1.7 .1 Oracle Oracle8i Standard Edition 8.1.7 Oracle Oracle8 8.0.6 |
| Not Vulnerable: | |
Discussion
Oracle Database Server ORACLE.EXE Buffer Overflow Vulnerability
The 'ORACLE.EXE' binary does not implement sufficient bounds checking on external data which is copied into local memory buffers.
An attacker may exploit this problem to corrupt sensitive regions of memory, in an effort to execute arbitrary code. Code will be executed with the privileges of the underlying server. This issue may only be exploited if a client application does not place bounds limits on externally supplied data before passing it to Oracle.
The 'ORACLE.EXE' binary does not implement sufficient bounds checking on external data which is copied into local memory buffers.
An attacker may exploit this problem to corrupt sensitive regions of memory, in an effort to execute arbitrary code. Code will be executed with the privileges of the underlying server. This issue may only be exploited if a client application does not place bounds limits on externally supplied data before passing it to Oracle.
Exploit / POC
Oracle Database Server ORACLE.EXE Buffer Overflow Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Oracle Database Server ORACLE.EXE Buffer Overflow Vulnerability
Solution:
Oracle has made fixes available. Administrators can download the patches at http://metalink.oracle.com by entering Bug Number 2620726.
The attached Oracle advisory also contains a release schedule for patches across all supported platforms.
Solution:
Oracle has made fixes available. Administrators can download the patches at http://metalink.oracle.com by entering Bug Number 2620726.
The attached Oracle advisory also contains a release schedule for patches across all supported platforms.