Skip to main content

Oracle Patches Database Security Flaw

posted onAugust 13, 2012
by l33tdawg

Oracle has issued a fix for a security weakness in its database product that was disclosed at the Black Hat security conference in July in Las Vegas.

At the conference, Oracle database security guru David Litchfield of Accuvant Labs outlined CVE-2012-3132, a vulnerability in the Oracle database server. The issue was one of multiple attacks that Litchfield demonstrated against the Oracle indexing architecture. The flaw allows authenticated remote users to execute arbitrary SQL commands via vectors involving CREATE INDEX with a CTXSYS.CONTEXT INDEXTYPE and DBMS_STATS.GATHER_TABLE_STATS.

While it is not exploitable by remote unauthenticated users, an attacker could exploit the issue as part of a privilege escalation attack and gain 'SYS' privileges.

Source

Tags

Oracle Security

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th