Home > Security News > Oracle accidentally exposes flaw, exploit
Security News:
EMAIL THIS

Oracle accidentally exposes flaw, exploit

By Bill Brenner, Senior News Writer
11 Apr 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Updated Wednesday, April 12 to include a statement from Oracle Corp.

Oracle Corp.'s next critical patch update (CPU) is a week away, but customers of the database giant already have a security hole to worry about -- and this one appears to have been accidentally released by the company itself.

According to Alexander Kornbrust, a well-known database security researcher and business director at German firm Red-Database-Security GmbH, Redwood Shores, Calif.-based Oracle accidentally posted information about the flaw -- including how to exploit it -- on its MetaLink customer support site.

More on Oracle security

Oracle releases critical, out-of-cycle patch

Oracle makes Microsoft patching look good

Researcher: Oracle failed to patch critical flaw

Oracle patches 82 critical flaws

In a posting on the Red-Database-Security Web site, Kornbrust said that on April 6, Oracle released a note on the MetaLink site with details about an unpatched flaw and exploit code affecting all versions of Oracle Database, from 9.2.0.0 through 10.2.0.3. He said the note was also displayed in the daily headlines section of the MetaLink site and sent to subscribers of the daily headline section.

He said the "high-risk, privilege escalation" vulnerability is due to an error in how Oracle Database handles certain specially crafted views created by unprivileged users. He said malicious users who gain "SELECT" privileges could exploit the flaw to insert, update or delete arbitrary data.

The French Security Incident Response Team (FrSIRT), a widely known vulnerability clearinghouse, analyzed the flaw and released its own advisory, labeling the vulnerability a moderate risk.

"In this case, not only [did] Oracle release detailed information on the vulnerability, but they also included the working exploit code on the MetaLink" site.
Alexander Kornbrust
Red-Database-Security,
After he became aware of it, Kornbrust said he e-mailed Oracle about the posting, and the company then removed the information from MetaLink. On the Red-Database-Security Web site, he criticized the company for doing something for which it usually lashes out at others.

"Oracle normally criticizes individuals and/or companies for releasing information about Oracle vulnerabilities," he said. "In this case, not only [did] Oracle release detailed information on the vulnerability, but they also included the working exploit code on the MetaLink" site.

An Oracle spokesperson said the company is investigating the incident.

"Oracle is aware that information regarding a security vulnerability was inadvertently posted to MetaLink, Oracle's Web support portal," she said in an e-mail. "We are currently investigating events that led to the posting and plan to provide our customers a patch that addresses this vulnerability in a future quarterly Critical Patch Update."

Until the security hole is patched, Kornbrust offered the following workarounds:

  • Sanitize the connect role and remove the CREATE VIEW and CREATE DATABASE LINK privilege from the connect role.
  • Removing the primary key from the base table is an option, though this could cause performance and integrity issues on the application.

    Tags: Database Security ManagementApplication Attacks (Buffer Overflows, Cross-Site Scripting)Information Security Laws, Investigations and EthicsVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Database Security Management
    IBM to acquire database security firm Guardium
    What is the best database patch management process?
    Unpatched vulnerability discovered in Microsoft SQL Server
    SQL injection continues to trouble firms, lead to breaches
    Oracle issues quarterly patches, fixes database flaws
    Database monitoring, encryption vital in tight economy, Forrester says
    Oracle to buy Sun Microsystems for $7.4 billion
    Oracle issues 43 updates, fixes serious database flaws
    Imperva assigns security risk levels to databases
    How to create configuration management plans to install DLP
    Database Security Management Research

    Application Attacks (Buffer Overflows, Cross-Site Scripting)
    Quiz: How to build secure applications
    Black box and white box testing: Which is best?
    Adobe warns of critical update for Reader, Acrobat 9.1.3
    9 Ways to Improve Application Security After an Incident
    Developers Need Help with Security Errors
    Buffer overflow tutorial: How to find vulnerabilities, prevent attacks
    SQL injection protection: A guide on how to prevent and stop attacks
    Experts rebuke programmers who use SQL injection as feature
    SANS: Application threats, website flaws pose biggest security threats
    Mozilla helps Adobe push out faster patches
    Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

    Information Security Laws, Investigations and Ethics
    Melissa Hathaway urges more cooperation, government attention to cybersecurity
    Cybersecurity czar candidate questions clout of new position
    DHS fills National Cybersecurity Center post
    FTC shutters rogue ISP for hosting malicious content, botnets
    Experts optimistic of Obama cybersecurity plan
    WH cybersecurity plan needs private sector guidance
    Obama announces creation of cybersecurity coordinator position
    Cybersecurity Act of 2009: Power grab, or necessary step?
    Face-off: Who should be in charge of cybersecurity?
    Feds should get private sector advice on cybersecurity

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    data encryption/decryption IC  (SearchSecurity.com)
    International Data Encryption Algorithm  (SearchSecurity.com)
    link encryption  (SearchSecurity.com)
    MD2  (SearchSecurity.com)
    MD4  (SearchSecurity.com)
    MD5  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts