Bugtraq mailing list archives

Re: Oracle 8 root exploit


From: levins () WESTNET COM (Adam and Christine Levin)
Date: Mon, 15 Nov 1999 10:05:47 -0500


On Sat, 13 Nov 1999, Tellier, Brock wrote:
OVERVIEW
A vulnerability exists in Oracle 8.1.5 for UN*X which may allow any user
to obtain root privileges.

Confirmed for Oracle 8.0.5 on Solaris 2.6 SPARC.  We don't allow rsh
connections though (shut off in /etc/inetd.conf), so that's a workaround
for some people to use.

-Adam


Current thread: