Oracle patches two holes in 9i database
Computerworld -
Oracle Corp. released patches for two security holes in its 9i database last week that could have allowed an attacker to take over or run code on affected systems.
The more serious of the two bugs is in the Net Listener component of 9i, which "listens" for client requests for use of the database, according to a security bulletin by U.K.-based Next Generation Security Software Ltd. (NGSSoftware), the company that originally discovered the flaws. A buffer-overflow problem in Net Listener could let an attacker overrun the memory assigned to the application, allowing attack code to be run in the database's security context, NGSSoftware said.
The hole is exploitable from remote computers and affects all Version 9 releases of Oracle9i running on Windows and VM, according to Oracle.
The second vulnerability is also the result of a buffer overflow, this time in Oracle's 9iAS Reports Server, NGSSoftware said. If an attacker overran the buffer in the software, he would be able to run code in the server's security context, which is often the local system context on Windows systems, the company said.
The flaw affects Oracle 9iAS Reports Server 1.0, but not 2.0, and any Oracle product containing Reports Server 6.0.8.18.0 and older, Oracle said.
Both patches are available to Oracle customers at the company's Metalink Web site, which requires registration.
Viruses
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Effectively Implementing Datacenter Automation
Effectively select and deploy the best datacenter automation solution today!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Aligning IT to Business: The Rising Importance of Application Delivery Networks
Application Delivery Networking (ADN) will play a vital role in helping enterprises incorporate strategic technologies to achieve business initiatives.
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
Security Pathways to Less Complexity
Find pathways to security solutions, possibly peace of mind about your information security.
Mitigate Risk, Lower Costs and Improve Network Efficiency
Create a stable IP network that not only meets today's challenges, but is flexible enough to also meet future demands.
