- Alexander Kornbrust Oracle Security Blog - http://blog.red-database-security.com -
Oracle CPU July 2007
Dieser Eintrag stammt von Alexander Kornbrust Am 17 Jul 2007 @ 22:06 In Oracle Security | 1 Kommentar
The Oracle [1] CPU July 2007 is out.
The CPU contains fixes for 46 Oracle vulnerabilities. Most of the vulnerabilities are coming from the usual suspects. Integrigy (8 of 14 EBusiness Suite vulns), Red-Database-Security (3 vulnerabilities), Argeniss, NGS, Joxean Koret. This time Imperva found also a vulnerability. Welcome to the usual suspects…
2 of [2] Integrigy’s SQL Injection (Thanks to Steven Kost for the info) vulnerabilities are remote exploitable without authentication.
My vulnerabilities are a SQL Injection vulnerability in Apex (fixed with Apex 3.0.1), SQL Injection vulnerability in dbms_prvtaqis and a critical vulnerability in database views. The view bug is similar (but not identical) to bugs fixed with [3] April 2006 and [4] October 2006 . By using a specially crafted view it is possible to Insert/Update/Delete via database views.
More infos soon on the analysis webpage of Red-Database-Security.
The first advisories and an analysis of the [5] Oracle CPU July 2007 are available on our website.
– Alex
Dieser Artikel wurde ausgedruckt ab Alexander Kornbrust Oracle Security Blog: http://blog.red-database-security.com
URL zum Artikel: http://blog.red-database-security.com/2007/07/17/oracle-cpu-july-2007/
URLs in this post:
[1] CPU July 2007: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul20
07.html
[2] Integrigy: http://www.integrigy.com/
[3] April 2006: http://www.red-database-security.com/advisory/oracle_modify_data_via_views.html
[4] October 2006: http://www.red-database-security.com/advisory/oracle_modify_data_via_inline_view
s.html
[5] Oracle CPU July 2007: http://www.red-database-security.com/advisory/oracle_cpu_jul_2007.html
Klicken hier zum Drucken.