Oracle Database Server EXTPROC Buffer Overflow Vulnerability
BID:8267
Info
Oracle Database Server EXTPROC Buffer Overflow Vulnerability
| Bugtraq ID: | 8267 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0634 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery is credited to David Litchfield and Chris Anley of Next Generation Security Software Ltd. |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.2 .0.2 Oracle Oracle9i Standard Edition 9.2 .0.1 Oracle Oracle9i Standard Edition 9.0.2 Oracle Oracle9i Standard Edition 9.0.1 .4 Oracle Oracle9i Standard Edition 9.0.1 .3 Oracle Oracle9i Standard Edition 9.0.1 .2 Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 9.0 Oracle Oracle9i Personal Edition 9.2 .0.2 Oracle Oracle9i Personal Edition 9.2 .0.1 Oracle Oracle9i Personal Edition 9.0.1 Oracle Oracle9i Enterprise Edition 9.2 .2 Oracle Oracle9i Enterprise Edition 9.2 .0.1 Oracle Oracle9i Enterprise Edition 9.0.1 Oracle Oracle9i Client Edition 9.2 .0.2 Oracle Oracle9i Client Edition 9.2 .0.1 Oracle Oracle8i Standard Edition 8.1.7 .4 Oracle Oracle8i Standard Edition 8.1.7 .1 Oracle Oracle8i Standard Edition 8.1.7 .0.0 Oracle Oracle8i Standard Edition 8.1.7 Oracle Oracle8i Standard Edition 8.1.6 Oracle Oracle8i Standard Edition 8.1.5 Oracle Oracle8i Enterprise Edition 8.1.7 .1.0 Oracle Oracle8i Enterprise Edition 8.1.7 .0.0 Oracle Oracle8i Enterprise Edition 8.1.6 .1.0 Oracle Oracle8i Enterprise Edition 8.1.6 .0.0 Oracle Oracle8i Enterprise Edition 8.1.5 .1.0 Oracle Oracle8i Enterprise Edition 8.1.5 .0.2 Oracle Oracle8i Enterprise Edition 8.1.5 .0.0 |
| Not Vulnerable: | |
Discussion
Oracle Database Server EXTPROC Buffer Overflow Vulnerability
The EXTPROC executable used by the Oracle Database Server is prone to a buffer overflow. Successful exploitation could result in arbitrary code execution with potentially elevated privileges.
** This issue is reportedly related to BID 4033. A reliable source has indicated that Oracle patches for the issue described in BID 4033 introduce this issue. Symantec has not been able to confirm this information.
The EXTPROC executable used by the Oracle Database Server is prone to a buffer overflow. Successful exploitation could result in arbitrary code execution with potentially elevated privileges.
** This issue is reportedly related to BID 4033. A reliable source has indicated that Oracle patches for the issue described in BID 4033 introduce this issue. Symantec has not been able to confirm this information.
Exploit / POC
Oracle Database Server EXTPROC Buffer Overflow Vulnerability
The discoverer of this vulnerability has reportedly developed a working exploit that is not publically available or known to be circulating in the wild.
The discoverer of this vulnerability has reportedly developed a working exploit that is not publically available or known to be circulating in the wild.
Solution / Fix
Oracle Database Server EXTPROC Buffer Overflow Vulnerability
Solution:
Oracle has made fixes available. Administrators can download the patches at http://metalink.oracle.com.
The attached Oracle advisory also contains a release schedule for patches across all supported platforms.
Solution:
Oracle has made fixes available. Administrators can download the patches at http://metalink.oracle.com.
The attached Oracle advisory also contains a release schedule for patches across all supported platforms.
References
Oracle Database Server EXTPROC Buffer Overflow Vulnerability
References:
References:
- Oracle Security Alert 57 (Oracle)
- Oracle Extproc Buffer Overflow (#NISR25072003) (NGSSoftware Insight Security Research
) - question about oracle advisory (Tina Bird
) - Re: question about oracle advisory (David Litchfield
) - Re: question about oracle advisory ("David Litchfield"
) - Update to the Oracle EXTPROC advisory ("NGSSoftware Insight Security Research"
)