NEWS Hot on the heels of its reported weakness in its server software, Oracle has been left red-faced again today as security experts uncovered a hole in its 8i database. According to researchers at the CERT lab in Carnegie Mellon University, a buffer overflow vulnerability in its flagship database software allows hackers remote control of the database server. On a Windows machine, the flaw could also allow intruders to wrest control of the underlying operating system. Gunter Ollmann, principal consultant at ISS (Internet Security Systems) warned that the vulnerability is potentially very serious. "Anything which can give remote access to a system is not good," he pointed out. With the help of some extra code, the vulnerability allows a malicious user to take over the privileges of the TNS listener process before authentication - so no username or password is required to gain access. A standard internet firewall should protect most companies from external attackers, although Ollman warned that firms without firewall protection or with misconfigured software could be at risk. Even with a firewall, businesses remain at risk from malicious attacks within company walls. Last month ISS discovered a similar flaw in Oracle Net8, leaving users of its hugely popular 7,8 and 8i databases open to external Denial of Service (DoS) attacks. Ollman said: "It's such a large package with a tremendous amount of code. The bigger it is, the more likely it is that flaws will creep in."
Oracle left red-faced by security flaw
Database hole revealed...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Latest Software stories
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Systems engineering: Best practice for development success
Systems engineering isn't just a technical activity in the product lifecycle—it determines the commercial viability of...
-
The virtual presenter's handbook
Web seminars -- or webinars -- are online seminars or presentations used to engage remote audiences with any content...
-
Use product development for competitive advantage
Remember when MP3 players just played music? Today, consumers want players that can host music, stream video, support...
Popular Software stories
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Project Manager
Black Rock Studio [A division of Disney Interactive Media Group] is currently recruiting for a Project Manager to...
-
Senior Marketing Executive - Poole - £30,000
I am representing a market leading company based in the Bournemouth / Poole area that are urgently looking for...
-
SAP Senior PC Product Costing Consultant - FICO (FI/CO) - End User - Up to £85,000
SAP Senior PC Product Costing Consultant - FICO (FI/CO) - End User - Up to £85,000SAP Senior PC Product...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




