Oracle Database Server PL/SQL Injection Flaws Let Remote Authenticated Users Gain Database Administrator Privileges
Categorie: Vulnerability Posted: 2005-01-20 by ReCall Views: 351 Source: Click here
Current Rating: Not rated
Details
Description: Several vulnerabilities were reported in Oracle Database Server. A remote authenticated user can gain elevated privileges.
NGSSoftware reported that a remote authenticated user can inject PL/SQL commands to gain database administrator privileges. A user can also exploit a buffer overflow [but the impact of the buffer overflow was not specified].
Additional details will be published by NGSSoftware on April 18, 2005.
Impact: A remote authenticated user can gain database administrator privileges.
Solution: The vendor has issued a fix (Critical Patch Update - January 2005), described at: