Database Administration (MOSC)

MOSC Banner

Has the extproc buffer overflow bug (#57) been fixed in 10.2?

edited Mar 19, 2012 7:17AM in Database Administration (MOSC) 1 commentAnswered
Hi all,

I'm looking for confirmation that I don't need to install patches or workarounds for this problem:

Utilizing an Oracle Listener configured with a TCP protocol address, a knowledgeable and malicious user can write an exploit that connects to an Oracle Database server's EXTPROC OS process without having to provide a database username and password. As such, it is possible to make arbitrary calls to the underlying OS and potentially gain unauthorized administrative access to the machine hosting the Oracle Database server. The EXTPROC functionality is installed by default in the Oracle Database installation if the "Typical Installation" option is chosen from the Oracle Universal Installer menu. EXTPROC is used by Oracle'

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center