Remote Compromise Vulnerability in Oracle 8 and 9

A remotely exploiable vulnerability exists in Oracle’s Database server versions 8 and 9 for Windows 2000 and Windows NT 4.0.

Ken Pfeil

February 6, 2002

2 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedFebruary 6, 2002, by Next Generation Security Software, LTD.

 

VERSIONSAFFECTED

 

  • Oracle 9 and Oracle 8 for Windows 2000 and Windows NT 4.0

 

DESCRIPTION

A vulnerability exists in Oracle’s Database server versions 8and 9 for Windows 2000 and Windows NT 4.0. Because no authentication is usedwhen the Procedural Language/Structured Query Language (PL/SQL) runs an externalprocedure it may be possible for an attacker to connect to the listener/extprocover TCP and call any function that the system has access to. A more detailedexplanation is available in the discoverer’s advisory.

 

 

VENDORRESPONSE

 

Oraclewas contacted last summer and is working on a patch to correct this issue. Aworkaround is to block the TNS Listener port (1521) behind a firewall and removethe PLSExtproc functionality if it is not being used. This can be done byremoving the entries located in the files tnsnames.ora and listener.ora.

 

CREDIT


Discoveredby David Litchfield.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like