Feeds

Oracle 9i Database, Ap Server bust six ways to Sunday

Tough break

  • alert
  • submit to reddit

Using blade systems to cut costs and sharpen efficiencies

Oracle admins are in for a busy time with the publication of no less than six vulnerabilities over the last week.

Four of the vulnerabilities are buffer overflow flaws affecting various components of Oracle9i Database Server. Then there's two flaws affecting Oracle9i Application Server, which pose denial of service risks... or worse.

Some are potentially very nasty indeed. Oracle describes them as critical and that's not the half of it...

The buffer overflows in Database server involve: the ORACLE.EXE binary, the TO_TIMESTAMP_TZ function, the TZ_OFFSET function and DIRECTORY parameter of Oracle9i Database Server.

These are explained in greater depth in the BugTraq advisories linked to above and the security section of Oracle's Web site.

The web site also gives more refers to two Oracle9i Application Server vulnerabilities (involving DAV_PUBLIC Directory
and the mod_oradav Module)

All vulnerabilities were posted to BugTraq, and patched published by Oracle, last weekend. Over the weekend security researchers have been digesting these reports, and coming up with some potentially unsettling conclusions.

David Litchfield, of NGSSoftware, the security firm that has carved something of a niche for itself in unearthed Oracle flaws (and did the lion's share of the work this time too), tells us the majority of the Oracle9i Database Server require an attacker to have a valid user name and password.

So the greatest risk here comes from a buffer overflow glitch within the Database Server's authentication process, which a post from NGSSoftware to BugTraq today explains in much greater depth. Various flavours of Database Server (8i, 8.1.7, 8.0.6) as well as Oracle9i are potentially vulnerable to this attack, according to NGSSoftware.

Combine that with an Oracle9i Application Server Format String Vulnerability, and we have a way an attacker might gain control of Ap Server and get around what firewall rules might otherwise guard against attack against (potentially vulnerable) Database Servers.

Oracle describes this as only a denial of service risk but the issue, albeit it tricky to exploit, seems to go deeper than this would suggest.

Litchfield, in masterly understatement, says these various vulnerabilities "need attention".

Once again: Oracle's patches can be obtained via links on its Web site here. ®

Related Stories

Oracle objects to Reg security coverage
Staying on top of Oracle's holes
How to hack unbreakable Oracle servers
Slammer: Why security benefits from proof of concept code

The smart choice: opportunity from uncertainty

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Attackers raid SWISS BANKS with DNS and malware bombs
'Retefe' trojan uses clever spin on old attacks to grant total control of bank accounts
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.