Description: A vulnerability has been reported in Oracle Database, which can be exploited by malicious users to compromise a vulnerable system.
The vulnerability is caused due to a boundary error in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure when processing the OWNER and NAME arguments to create an SQL query. This can be exploited to cause a buffer overflow by passing overly long OWNER and NAME arguments to the affected procedure.
Successful exploitation allows execution of arbitrary code.
The vulnerability is reported in version 10g Release 2 with all Critical Patch Updates as of February 2007. Other versions may also be affected.
Solution: A fix is reportedly scheduled for a future Critical Patch Update.
Provided and/or discovered by: Discovered by an anonymous researcher and reported via iDefense Labs.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.