Remote Compromise Vulnerability in Oracle 8 and 9
A remotely exploiable vulnerability exists in Oracle’s Database server versions 8 and 9 for Windows 2000 and Windows NT 4.0.
February 6, 2002
ReportedFebruary 6, 2002, by Next Generation Security Software, LTD.
VERSIONSAFFECTED
Oracle 9 and Oracle 8 for Windows 2000 and Windows NT 4.0
DESCRIPTION
A vulnerability exists in Oracle’s Database server versions 8and 9 for Windows 2000 and Windows NT 4.0. Because no authentication is usedwhen the Procedural Language/Structured Query Language (PL/SQL) runs an externalprocedure it may be possible for an attacker to connect to the listener/extprocover TCP and call any function that the system has access to. A more detailedexplanation is available in the discoverer’s advisory.
VENDORRESPONSE
Oraclewas contacted last summer and is working on a patch to correct this issue. Aworkaround is to block the TNS Listener port (1521) behind a firewall and removethe PLSExtproc functionality if it is not being used. This can be done byremoving the entries located in the files tnsnames.ora and listener.ora.
CREDIT
Discoveredby David Litchfield.
About the Author
You May Also Like