Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 40 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » April 2006 » Oracle has released details of a 0-day vulnerability including exploit code on Metalink

[Previous entry: "Back blogging again about Oracle Security"] [Next entry: "Oracle Slip-up Results In Leaked Exploit Information"]

Oracle has released details of a 0-day vulnerability including exploit code on Metalink

April 10th, 2006 by Pete

Post to del.icio.us   Post to Furl   Digg!

Today Alex let me know that Oracle released a note on the knowledge base on Metalink that details an unfixed security vulnerablity (0-day), including test cases (exploit code) that affects all versions of Oracle from 9.2.0.0 to 10.2.0.3. The note has now been removed but was in the headlines section and was titled "363848.1 � A User with SELECT Object Privilege on Base Tables Can Delete Rows from a View". Alex has informed Oracle that it is not a good idea to release this sort of information on unfixed security bugs.

There is a detailed discussion of the issue on Alex's site in a page titled "Read-only user can modify data via views". This page details the issue and also includes exploit code (the actual method of exploit is censored out).

Dr. Christian Kleinew�chter and Swen Th�mmler from infinity3 GmbH found the issue.

April 2006
SMTWTFS
      1
2345678
9101112131415
16171819202122
23242526272829
30      

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0




View Pete Finnigan's profile on LinkedIn

Pete Finnigan

Create Your Badge



Valid XHTML 1.0!