34 flaws found in Oracle database software
Company plans to issue security alert 'soon'
August 3, 2004 12:00 PM ETComputerworld -
Oracle Corp. will soon issue patches to fix 34 different vulnerabilities in its database software that were disclosed to it early this year by a British bug hunter.
The flaws, a majority of which are serious, affect both existing and previous versions of Oracle's database technology, said David Litchfield, managing director of Surrey, England-based Next Generation Security Software Ltd.
"They include buffer overflows, SQL injection issues and a whole range of other minor issues," said Litchfield, who discovered the flaws. He said that he reported them to Oracle in January and February.
"Some of them can be exploited without a user ID and password, while others require them," Litchfield said. Nearly 90% of the flaws allow attackers to potentially gain complete administrative control of vulnerable database servers, he said.
Oracle confirmed the existence of the flaws, which were discussed publicly at last week's Black Hat security conference in Las Vegas, but did not offer any further comment. In an e-mailed statement, a company spokeswoman said that Oracle had fixed the flaws and would issue a security alert "soon."
According to Litchfield, some of the vulnerabilities are easy to exploit, whereas others require attackers to have fairly detailed technology skills. He said that his company has exploits available that take advantage of the flaws but that it has no plans to release them publicly.
Litchfield also claimed that Oracle told him patches were available to fix the problems a few months ago. But the company appears to be waiting for an updated patching process to be ready before releasing the fixes, he said.
"It is my opinion that they could have run the old patching process up until the time that the new patching procedure was ready. There really is no point in exposing users to unnecessary risks," he said.
Litchfield and his brother, Michael Litchfield, have discovered several previous vulnerabilities in Oracle software, including 20 on the very day the database giant launched its "Unbreakable" marketing campaign.
The discovery of such flaws by people who go specifically looking for them should come as no surprise given the size and complexity of today's application software, said Bruce Schneier, co-founder and chief technology officer of Counterpane Internet Security Inc. in Mountain View, Calif.
"This could happen to anyone. It tends to happen to Microsoft a lot," Schneier said. "The bugs are already there. All you can do is react when somebody points them out."
The companies that make it their mission to discover such flaws are often driven by a "bunch ofmotivations," Schneier said.
"Some companies make their name finding bugs," he said. "Some academics do it because they are trying to do research projects. People who find the stuff have their motives, and it's not all altruism."
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Centralized Data Backup and Your WAN
Is your organization prepared to tackle the massive challenge of protecting your data in a cost effective and timely manner? With a growing...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...
Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...
Open Source Security Myths Dispelled
(Source: Astaro) Open Source Software is computer software whose source code is available to the general public. This openly viewable nature...
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Best Practices for Backing Up VMware® with Veritas NetBackup™
VMware® is used by enterprises large and small to increase the efficiency and cost-effectiveness of their IT operations. With this in mind, Symantec...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
