SHARE
Facebook X Pinterest WhatsApp

Buffer Overflows Patched in Oracle 9i Database

Written By
thumbnail
Ryan Naraine
Ryan Naraine
Sep 1, 2020
ServerWatch content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More



British security research firm NGSSoftware has discovered multiple
security vulnerabilities in Oracle’s database server software. The firm is warning that the most serious flaw could lead to system takeover.

Oracle issued a fix for multiple vulnerabilities in its database server software.

The vulnerabilities affect the Oracle9i Database (both enterprise and standard editions) and can be exploited by malicious database users to compromise the system and gain escalated privileges, the research firm warned.

Security alerting service Secunia rates the flaws as “moderately
critical.”

Oracle 9i Database users are urged to upgrade to version 9.2.0.4 and apply Patch 3 from the company’s Metalink site.

The database management software, used by large scale enterprises to store and access data across numerous platforms, contains a security hole due to boundary errors in two functions and could cause buffer overflows. NGSSoftware said the buffer overflow could be caused by supplying an overly long character string.

Two separate vulnerabilities are being caused due to boundary errors in the “FROM_TZ” function and in the “TIME_ZONE” parameter, NGSSoftware said.

“Successful exploitation of the vulnerabilities may allow a malicious, unprivileged database user to execute arbitrary code with either SYSTEM or ORACLE privileges.”

This article was originally published on internetnews.com.

Recommended for you...

What Is a Container? Understanding Containerization
What Is a Print Server? | How It Works and What It Does
Nisar Ahmad
Dec 8, 2023
6 Best Linux Virtualization Software for 2024
What Is a Network Policy Server (NPS)? | Essential Guide
ServerWatch Logo

ServerWatch is a top resource on servers. Explore the latest news, reviews and guides for server administrators now.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.