All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
About Hackers
Analysis
News
Glossary
Weblog



 
Virus Encyclopedia
Virus Encyclopedia

Learn about worms, viruses, Trojans and more in our Virus Encyclopedia.

About Spam
About Spam

Read about spam and spammers in our About Spam section.

 

  Home / Hackers / About Hackers / Software Vulnerabilities / Examples and Descriptions / SA38353

Oracle Database Two Security Issues

Secunia ID

SA38353

Release Date

08 Feb 2010

Last Change

11 Feb 2010

Criticality

Less Critical

Solution Status

Unpatched

Software

Oracle Database 10.x
Oracle Database 11.x

Where

From local network

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.


Privilege escalation

This covers vulnerabilities where a user is able to conduct certain tasks with the privileges of other users or administrative users.

This typically includes cases where a local user on a client or server system can gain access to the administrator or root account thus taking full control of the system.


Description

David Litchfield has reported two security issues in Oracle Database, which can be exploited by malicious users to gain escalated privileges and compromise a vulnerable system.

1) Access to procedures within the "DBMS_JVM_EXP_PERMS" package is not restricted, which can be exploited to modify the Java policy table via the "IMPORT_JVM_PERMS" procedure.

This can be exploited to e.g. execute arbitrary operating system commands.

2) An error in the argument handling of the "DBMS_JAVA.SET_OUTPUT_TO_JAVA" procedure can be exploited to execute SQL commands as the SYS user.

This can be exploited to gain DBA user privileges.

NOTE: Successful exploitation allows bypassing Oracle Label Security.

Solution

Grant only trusted users access to the application.

Reported by

David Litchfield

Original Advisory

https://media.blackhat.com/bh-dc-10/video/Litchfield_David/BlackHat-DC-2010-Litchfield-Oracle11g-video.m4v
http://www.databasesecurity.com/HackingAurora.pdf
http://www.databasesecurity.com/bh-DC2010.pdf




 

Copyright © 1996 - 2010
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com