Jump to content

Oracle/Linux


andsome
 Share

Recommended Posts

The following could interest Linux/Oracle users.

"The struggle itself towards the heights

is enough to fill a man's heart."

Albert Camus (1913-60); French-Algerian philosopher.

- Buffer overflow in Oracle -

Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)

Madrid, October 20, 2003 - SecurityTracker has reported, at

http://www.securitytracker.com/alerts/2003/Oct/1007956.html, a buffer

overflow vulnerability in the Orcale database system, which could allow a

local user to run code and increase privileges on the affected system.

This problem lies in the fact that a local user could pass a large input

string to the database to trigger a buffer overflow and overwrite the EIP

register to execute arbitrary code. A demo exploit of the vulnerability has

already been published.

According to reports, the 'oracle' and 'oracleO' binaries are affected. As

the binaries are reportedly configured with set user id (setuid) 'oracle'

user privileges, the arbitrary code will run with the privileges of the

'oracle' user. The report indicates that version 9.2.0.4.0 is vulnerable on

Linux and AIX, although other versions could also be affected.

NOTE: The address above may not show up on your screen as a single line.

This would prevent you from using the link to access the web page. If this

happens, just use the 'cut' and 'paste' options to join the pieces of the

URL.

------------------------------------------------------------

The 5 viruses most frequently detected by Panda ActiveScan, Panda Software's

free online scanner: 1)Parite.B; 2)Blaster; 3)Istbar.H; 4)Gibe.C;

5)Bugbear.B.

------------------------------------------------------------

To unsubscribe from Oxygen3 24h-365d, please visit:

http://www.pandasoftware.com/unsubscribe.asp

To contact with Panda Software, please visit:

http://www.pandasoftware.com/about/contact/

------------------------------------------------------------

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy