Short Name |
DB:ORACLE:ORACLE-DSI
|
Severity |
Critical
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
DB
|
Keywords |
Oracle Database DBMS_SNAP_INTERNAL Package Buffer Overflow
|
Release Date |
2008/01/28
|
Update Number |
1213
|
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
DB: Oracle Database DBMS_SNAP_INTERNAL Package Buffer Overflow
This signature detects attempts to exploit a known vulnerability in the Oracle Database Server. It is due to a boundary error within the DBMS_SNAP_INTERNAL package of the product. A remote authenticated attacker can send an overly long input to the affected package and cause a buffer overflow. A successful attack allows arbitrary code injection and execution with the privileges of the server process, usually System/root.
Extended Description
Oracle has released a Critical Patch Update advisory for April 2007 to address these vulnerabilities for supported releases. Earlier unsupported releases are likely to be affected by these issues as well.
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats. Various levels of authorization are needed to leverage some of the issues, but other issues do not require any authorization. The most severe of the vulnerabilities could possibly expose affected computers to complete compromise.
Affected Products
- HP Oracle for OpenView 8.1.7
- HP Oracle for OpenView 9.1.01
- HP Oracle for OpenView 9.2
- HP Oracle for OpenView for Linux LTU
- IBM Tivoli Compliance Insight Manager 6.0
- IBM Tivoli Compliance Insight Manager 7.0
- IBM Tivoli Compliance Insight Manager 8.0
- Oracle Application Server 10.1.2.0.0
- Oracle Application Server 10.1.2.0.2
- Oracle Application Server 10.1.2.2
- Oracle Application Server 10.1.3.0
- Oracle Application Server 10.1.3.2.0
- Oracle Application Server 10.1.4.1.0
- Oracle Application Server 7.0.4.4
- Oracle Application Server 9.0.4.3
- Oracle Collaboration Suite Release 1 10.1.2
- Oracle E-Business Suite 12.0.0
- Oracle E-Business Suite 11i 11.5.10
- Oracle E-Business Suite 11i 11.5.10.2
- Oracle E-Business Suite 11i 11.5.10 CU2
- Oracle E-Business Suite 11i 11.5.7
- Oracle E-Business Suite 11i 11.5.8
- Oracle E-Business Suite 11i 11.5.9
- Oracle E-Business Suite 12 12.0.0
- Oracle Enterprise Manager 9i 9.0.1 5
- Oracle Enterprise Manager 9i Release 2 9.2.0 7
- Oracle Enterprise Manager 9i Release 2 9.2.0 8
- Oracle JD Edwards EnterpriseOne 8.96
- Oracle JD Edwards EnterpriseOne 8.96.11
- Oracle JD Edwards OneWorld Tools SP23
- Oracle Oracle10g Application Server 10.1.0 .0.4
- Oracle Oracle10g Application Server 10.1.0 .5
- Oracle Oracle10g Application Server 10.1.2 .0.1
- Oracle Oracle10g Application Server 10.1.2 .0.2
- Oracle Oracle10g Application Server 10.1.2 .1.0
- Oracle Oracle10g Application Server 10.1.2 .2.0
- Oracle Oracle10g Application Server 10.1.3 .0.0
- Oracle Oracle10g Application Server 10.1.3 .1.0
- Oracle Oracle10g Application Server 10.1.3 .2.0
- Oracle Oracle10g Application Server 9.0.4 3
- Oracle Oracle10g Enterprise Edition 10.1.0 .0.2
- Oracle Oracle10g Enterprise Edition 10.1.0 .0.4
- Oracle Oracle10g Enterprise Edition 10.1.0 .5
- Oracle Oracle10g Enterprise Edition 10.2.0 .1
- Oracle Oracle10g Enterprise Edition 10.2.0 .2
- Oracle Oracle10g Enterprise Edition 10.2.0 .3
- Oracle Oracle10g Personal Edition 10.1.0 .0.2
- Oracle Oracle10g Personal Edition 10.1.0 .0.4
- Oracle Oracle10g Personal Edition 10.1.0.5
- Oracle Oracle10g Personal Edition 10.2.0 .1
- Oracle Oracle10g Personal Edition 10.2.0 .2
- Oracle Oracle10g Personal Edition 10.2.0 .3
- Oracle Oracle10g Standard Edition 10.1.0 .0.2
- Oracle Oracle10g Standard Edition 10.1.0 .0.4
- Oracle Oracle10g Standard Edition 10.1.0 .0.5
- Oracle Oracle10g Standard Edition 10.2.0.1
- Oracle Oracle10g Standard Edition 10.2.0 .2
- Oracle Oracle10g Standard Edition 10.2.0 .3
- Oracle Oracle9i Application Server 9.2.0 .0.7
- Oracle Oracle9i Application Server 9.2.0 .8
- Oracle Oracle9i Enterprise Edition 9.0.1 .5
- Oracle Oracle9i Enterprise Edition 9.2.0 .0.1
- Oracle Oracle9i Enterprise Edition 9.2.0 .0.5
- Oracle Oracle9i Enterprise Edition 9.2.0.7.0
- Oracle Oracle9i Enterprise Edition 9.2.0.8.0
- Oracle Oracle9i Personal Edition 9.0.1 .5
- Oracle Oracle9i Personal Edition 9.2.0 .0.1
- Oracle Oracle9i Personal Edition 9.2.0 .0.5
- Oracle Oracle9i Personal Edition 9.2.0 .7
- Oracle Oracle9i Personal Edition 9.2.0 .8
- Oracle Peoplesoft Enterprise 8.22.14
- Oracle Peoplesoft Enterprise 8.47.12
- Oracle Peoplesoft Enterprise 8.48.08
- Oracle Peoplesoft Enterprise 8.9
- Oracle PeopleSoft Enterprise Human Capital Management 8.9
- Oracle PeopleSoft Enterprise PeopleTools 8.22
- Oracle PeopleSoft Enterprise PeopleTools 8.47
- Oracle PeopleSoft Enterprise PeopleTools 8.48
- Oracle Secure Enterprise Search 10g Release 1 10.1.6
References