Oracle, Microsoft warn of database flaws

Friday, 25 July 2003, 10:49 AM EST

Both Oracle Corp. and Microsoft Corp. have discovered new vulnerabilities in their databases, the two companies reported.

Microsoft on Wednesday issued a cumulative patch for three newly discovered holes. The first of these vulnerabilities, named-pipe hijacking, is the only one that could allow an attacker to gain inappropriate access to data, but it's not exploitable remotely—rather, the attacker would need to be an authenticated, local user.

Named-pipe hijacking consists of a flaw in the checking method for a named pipe. A named pipe is a specifically named one- or two-way channel for communication between a pipe server and one or more pipe clients. Upon system startup, SQL Server creates and listens on a specific, named pipe for incoming server connections. The named pipe is checked to verify which connection attempts can log on and execute queries to the system on which SQL Server is running.

[ Read more ]




Spotlight

A data security guy's musings on the OPM data breach train wreck

There is still way too much apathy when it comes to data-centric security. Given the sensitive data the OPM was tasked with protecting, it should have had state-of-the-art data protection, but instead it has become the poster child for IT security neglect.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Tue, Jul 28th
    COPYRIGHT 1998-2015 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //