Oracle Patches Database Security Flaw
Oracle has issued a fix for a security weakness in its database product that was disclosed at the Black Hat security conference in July in Las Vegas.
At the conference, Oracle database security guru David Litchfield of Accuvant Labs outlined CVE-2012-3132, a vulnerability in the Oracle database server. The issue was one of multiple attacks that Litchfield demonstrated against the Oracle indexing architecture. The flaw allows authenticated remote users to execute arbitrary SQL commands via vectors involving CREATE INDEX with a CTXSYS.CONTEXT INDEXTYPE and DBMS_STATS.GATHER_TABLE_STATS.
While it is not exploitable by remote unauthenticated users, an attacker could exploit the issue as part of a privilege escalation attack and gain 'SYS' privileges.