The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Three years and ten months without a patch


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
From: "David Litchfield" <davidl@ngssoftware.com.>
To: <ntbugtraq@listserv.ntbugtraq.com.>, <bugtraq@securityfocus.com.>,
Subject: Three years and ten months without a patch
Date: Tue, 15 Nov 2005 13:12:41 -0000
MIME-Version: 1.0
Content-Type: text/plain;
        charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Office Outlook, Build 11.0.6353
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
Thread-Index: AcXp5kKWO9hS4thASuGBfMV718k72A==
Message-Id: <20051115125900.7B3FE15F516@mail.ngssoftware.com.>
X-Virus-Scanned: antivirus-gw at tyumen.ru

Whilst looking over old Oracle bugs I discovered that a _fully_ _patched_
8.1.7.4 Oracle server is still vulnerable to the old extproc flaw
[http://www.ngssoftware.com/advisories/oraplsextproc.txt&#093;; this flaw, when
exploited, allows a remote attacker without a userID and password to take
control of the server. Why, you may ask, has a supported product gone for so
long without a patch for a serious problem that was made public 3 years and
10 months ago and reported to Oracle over 4 years ago? The answer, according
to Alert 57
[http://www.oracle.com/technology/deploy/security/pdf/2003alert57.pdf&#093;, is
that Oracle outright decided not to fix it. They claim "architectural
constraints" are the problem even though they managed to overcome these same
constraints on newer versions of Oracle. 

Users of 8.1.7.4 would do well to heed the advice offered in Alert 57 if
they've not already done so.

Cheers,
David Litchfield
http://www.databasesecurity.com/
http://www.ngssoftware.com/

More commentary on this available here
http://www.databasesecurity.com/oracle-commentary.htm



<< Previous INDEX Search src Set bookmark Go to bookmark Next >>

ПОДПИШИСЬ НА ЖУРНАЛ Linux Format 2012!

Журнал "Linux Format" (Линукс Формат)- Единственный в России и странах СНГ журнал на русском языке, посвящённый Linux и свободному ПО. Журнал для IT-директоров, IT-менеджеров, программистов, системных администраторов, учителей школ и преподавателей ВУЗов и всех пользователей ПК. В каждом выпуске: Новости индустрии OpenSource, обзоры новинок свободного ПО, обучающие и методические статьи.

Каждый, кто оформит подписку, получает бонусы и подарки- объёмные наклейки на системный блок, диск с архивом номеров за 2005-2011 г.г. и ежемесячно электронную версию журнала в pdf-формате.

Оформить подписку на год


  Закладки на сайте
  Проследить за страницей
Created 1996-2012 by Maxim Chirkov  
ДобавитьРекламаВебмастеруГИД  
RUNNet TopList