[原文]Multiple unspecified vulnerabilities in Oracle Database server 188.8.131.52, 184.108.40.206, 220.127.116.11, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB17 in the Oracle Text component and (2) DB18 in the Program Interface Network component. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB17 involves SQL injection in the (a) VALIDATE_STATEMENT and BUILD_DML functions in CTXSYS.DRILOAD; (b) CLEAN_DML function in CTXSYS.DRIDML; (c) GET_ROWID function in CTXSYS.CTX_DOC; (d) BROWSE_WORDS function in CTXSYS.CTX_QUERY; and (e) ODCIINDEXTRUNCATE, ODCIINDEXDROP, and ODCIINDEXDELETE functions in CATINDEXMETHODS.
Oracle Database Text CTXSYS.DRILOAD Multiple Procedure SQL Injection
Remote / Network Access
Loss of Confidentiality,
Loss of Integrity
Oracle Database Server contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the CTXSYS.DRILOAD package not properly sanitizing user-supplied input to the VALIDATE_STATEMENT or BUILD_DML procedures. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
Currently, there are no known workarounds or upgrades to correct this issue. However, Oracle has released a patch (Jan2006 Critical Patch Update) to address this vulnerability.