You are here: silicon.com > Software > Applications

Applications

Oracle left red-faced by security flaw

Database hole revealed...

By Sally Watson

Published: 4 July 2001 16:16 GMT

Hot on the heels of its reported weakness in its server software, Oracle has been left red-faced again today as security experts uncovered a hole in its 8i database.

According to researchers at the CERT lab in Carnegie Mellon University, a buffer overflow vulnerability in its flagship database software allows hackers remote control of the database server. On a Windows machine, the flaw could also allow intruders to wrest control of the underlying operating system.

Gunter Ollmann, principal consultant at ISS (Internet Security Systems) warned that the vulnerability is potentially very serious. "Anything which can give remote access to a system is not good," he pointed out.

With the help of some extra code, the vulnerability allows a malicious user to take over the privileges of the TNS listener process before authentication - so no username or password is required to gain access.

A standard internet firewall should protect most companies from external attackers, although Ollman warned that firms without firewall protection or with misconfigured software could be at risk. Even with a firewall, businesses remain at risk from malicious attacks within company walls.

Last month ISS discovered a similar flaw in Oracle Net8, leaving users of its hugely popular 7,8 and 8i databases open to external Denial of Service (DoS) attacks.

Ollman said: "It's such a large package with a tremendous amount of code. The bigger it is, the more likely it is that flaws will creep in."

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Web Applications Vulnerability Tester

Title: Web Applications Vulnerability Tester / Penetration Tester Salary: market rates but probably 40k to 60k Company: online / ecommerce company ...

Firewall Engineer

My client a global leading Cisco Gold Partner and IT Managed Services Company require a Firewall engineer will work as part of a team, working on ...

IT Security Analyst

Respond when alerted to security events, whether in real time via monitoring tools or through log analysis.Work individually and with other incident ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: