Oracle9i Database Buffer Overflow Vulnerability in iSQL*Plus | Internet News

Oracle9i Database Buffer Overflow Vulnerability in iSQL*Plus

Written By
Forrest Stroud
Forrest Stroud
Nov 5, 2002
1 minute read


A potential buffer overflow security vulnerability has been discovered in the iSQL*Plus component of Oracle9i Database. All versions of Oracle9i, including the recently released Oracle9i Database Release 2, are susceptible to the vulnerability. Oracle has issued a severity level of 2 for this vulnerability.

A malicious user could take advantage of the vulnerability to pass a USERID parameter that may result in a remote buffer overflow exploit against iSQL*Plus. SQL*Plus is not affected by the exploit.

Future releases of Oracle Database will contain the fix by default, and patches are available from the Oracle Worldwide Support Services web site for current releases (accessible using Bug Number 2581911).

Credit goes to David Litchfield of Next Generation Security Software Limited for discovering the potential security vulnerability and bringing it to Oracle’s attention.

Additional information on the vulnerability and download links for the patch are available at
http://otn.oracle.com/deploy/security/pdf/2002alert46rev1.pdf.

Back to Database Journal Home

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.