Bugtraq mailing list archives
Security Bug in Oracle
From: aleph1 () SECURITYFOCUS COM (Elias Levy)
Date: Tue, 17 Aug 1999 09:22:32 -0700
---------- Forwarded message ---------- Date: Mon, 16 Aug 1999 23:51:53 +0200 From: Gilles PARC <gparc () online fr> Subject: Security Bug in Oracle Hi Listers, I discover a new security problem with Oracle on Unix. Once again, it's with a setuid program. Do not confuse with a similar problem corrected by ORACLE some month ago with a patch called setuid_patch.sh. NEW PROBLEM : if you have installed Oracle Intelligent agent, you will find in $ORACLE_HOME/bin a program called dbsnmp. This program is setuid root and was DELIBERATELY EXCLUDED by Oracle in the forementioned patch. The security hole resides in the fact that this program executes a tcl script ( nmiconf.tcl ) located by default in $ORACLE_HOME/network/agent/config. Needless to say that you can easily bypass this default and have your own malicious nmiconf.tcl script run under root privileges. I verify this on HP-UX 10.20 with Oracle 7.3.3 and 8.0.4.3 on AIX 4.3 with Oracle 8.0.5.1 But it's probably Unix generic. Regards Gilles Parc Email: gparc () mail dotcom fr carpe diem !! ----- End forwarded message ----- -- Elias Levy Security Focus http://www.securityfocus.com/
Current thread:
- Re: [RHSA-1999:028-01] Buffer overflow in libtermcap tgetent(), (continued)
- Re: [RHSA-1999:028-01] Buffer overflow in libtermcap tgetent() Aaron Campbell (Aug 19)
- Microsoft Security Bulletin (MS99-030) Aleph One (Aug 20)
- Re: [RHSA-1999:028-01] Buffer overflow in libtermcap tgetent() Alan Cox (Aug 22)
- libtermcap exploit fix ... smashcap.c Hudin Lucian (Aug 22)
- Re: [RHSA-1999:028-01] Buffer overflow in libtermcap tgetent() Pavel Kankovsky (Aug 26)
- OCE' 9400 plotters Larry W. Cashdollar (Aug 19)
- Re: OCE' 9400 plotters Patrick Cantwell (Aug 23)
- Re: [RHSA-1999:028-01] Buffer overflow in libtermcap tgetent() Tymm Twillman (Aug 19)
- Re: [RHSA-1999:028-01] Buffer overflow in libtermcap tgetent() Olaf Kirch (Aug 18)
- Re: [RHSA-1999:028-01] Buffer overflow in libtermcap tgetent() Martin Schulze (Aug 19)
- Re: Security Bug in Oracle Jonathan A. Zdziarski (Aug 27)
- [RHSA-1999:030-02] Buffer overflow in cron daemon Bill Nottingham (Aug 27)