Reported February 17, 2003, by NGSSoftware.

 

 

VERSIONS AFFECTED

 

  • Oracle Database Server

 

DESCRIPTION

 

A vulnerability in Oracle Database Server can result in remote compromise of the vulnerable server. This vulnerability stems from an overflow in the database server's authentication process. By supplying an overly long username when attempting to log on to the database server, an attacker can overflow a stack-based buffer, thereby overwriting the saved return address. Any arbitrary code that the attacker supplies would execute with the same privileges as the user running the service. For more details about this vulnerability, see the discoverer’s web site.

 

VENDOR RESPONSE

 

Oracle has released an alert regarding this vulnerability.

 

CREDIT          

Discovered by NGSSoftware.