[VulnWatch] Update to the Oracle EXTPROC advisory

From: NGSSoftware Insight Security Research (nisr_at_nextgenss.com)
Date: 09/12/03

  • Next message: Frog Man: "[VulnWatch] vbPortal : SQL Injection"
    To: <bugtraq@securityfocus.com>, <NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM>, <vulnwatch@vulnwatch.org>
    Date: Fri, 12 Sep 2003 13:30:10 +0100
    
    

    Hello,
    Please note that Oracle has updated the extproc buffer overrun advisory.
    There was some confusion caused because the intial Oracle advisory stated
    that a username and password were required to exploit the overflow which was
    contrary to the results of our research; we concluded that no user ID or
    password was necessary. Whilst I answered many of the mails querying this
    discrepancy, for those that I did not have a chance to reply to, please
    accept my apologies. The updated Oracle can be found here :
    http://otn.oracle.com/deploy/security/pdf/2003alert57.pdf . In summary,
    Oracle 9i Database Release 2, Oracle 9i Database Release 1 and Oracle 8i
    Database (8.1.x) are all vulnerable and that "Risk to exposure is high, as a
    valid username and password is not needed in all cases to exploit this
    potential vulnerability."
    Cheers,
    David Litchfield
    NGSSoftware Ltd
    http://www.nextgenss.com/
    +44(0)208 401 0070

    NGSSoftware's SQuirrel for Oracle, an advanced security audit tool for
    Oracle, checks for these vulnerabilities. More information is available from
    http://www.nextgenss.com/products/squirrelfororacle.htm .


  • Next message: Frog Man: "[VulnWatch] vbPortal : SQL Injection"

    Relevant Pages

    • Update to the Oracle EXTPROC advisory
      ... Please note that Oracle has updated the extproc buffer overrun advisory. ... that a username and password were required to exploit the overflow which was ... potential vulnerability." ...
      (Bugtraq)
    • Re: Oracle hash-list?
      ... password AND the username. ... Using pre-computed hashes will be difficult ... find 'online' passwords crackers for oracle. ...
      (Pen-Test)
    • Re: Connecting to an Oracle database
      ... the username and the password. ... The Server name is the name of the computer hosting Oracle. ... > computer where the database is. ...
      (borland.public.delphi.database.ado)
    • Re: Possible variation on "Invalid name pattern" exception
      ... and the Oracle JDBC driver cheerfully assists ... Oracle allows me to log in with this username without complaint, ... > ArrayDescriptor when I qualify the NAME_LIST with the User name, ...
      (comp.lang.java.databases)
    • Re: How to invoke access application through command promt
      ... multiple users are going to use the application with different usernames and ... I have not created any access username and password. ... >> providing oracle username and password. ... > You cannot do this via startup switches. ...
      (microsoft.public.access.forms)