Oracle FAQ | Your Portal to the Oracle Knowledge Grid |
![]() |
![]() |
Home -> Community -> Mailing Lists -> Oracle-L -> alert #51 more detail
Date: Mon, 17 Feb 2003 14:09:56 -0800
To: bugtraq_at_securityfocus.com
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
NGSSoftware Insight Security Research Advisory
Name: Oracle unauthenticated remote system compromise
Systems Affected: All platforms; Oracle9i Database Release 2, 9i Release 1,
8i, 8.1.7, 8.0.6
Severity: Critical Risk
Category: Remote System Buffer Overrun
Vendor URL: http://www.oracle.com
Author: Mark Litchfield (mark_at_ngssoftware.com)
Date: 16th February 2003
Advisory number: #NISR16022003a
Description
Details
C:\ora9ias\BIN>loadpsp -name -user LONGUSERNAME/tiger_at_iasdb myfile
Fix Information
http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf
NGSSoftware advise Oracle database customers to review and install the patch as a matter of urgency.
A check for these issues has been added to NGSSQuirreL for Oracle, a comprehensive automated vulnerability assessment tool for Oracle Database Servers of which more information is available from the NGSSite
http://www.ngssoftware.com/software/squirrelfororacle.html
It is further recommend that Oracle DBAs have their network/firewall administrators ensure that the database server is protected from Internet sourced traffic.
Further Information
http://www.ngssoftware.com/papers/non-stack-bo-windows.pdf http://www.ngssoftware.com/papers/ntbufferoverflow.html http://www.ngssoftware.com/papers/bufferoverflowpaper.rtf http://www.ngssoftware.com/papers/unicodebo.pdf
About NGSSoftware
http://www.ngssoftware.com/
http://www.ngsconsulting.com/
Telephone +44 208 401 0070
Fax +44 208 401 0076
enquiries_at_ngssoftware.com
--
Fat City Network Services -- 858-538-5051 http://www.fatcity.com San Diego, California -- Mailing list and web hosting services ---------------------------------------------------------------------To REMOVE yourself from this mailing list, send an E-Mail message to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing). Received on Mon Feb 17 2003 - 12:18:54 CST
![]() |
![]() |