- Alexander Kornbrust Oracle Security Blog - http://blog.red-database-security.com -
Oracle Patch CPU January 2008 is out…
Dieser Eintrag stammt von Alexander Kornbrust Am 15 Jan 2008 @ 22:13 In Oracle Security | 1 Kommentar
Oracle just released their latest [1] Oracle Critical Patch Update (CPU) January 2008. As promised in the prelease announcement the patch contains 8 fixes for the database itself. As usual most of the vulnerabilities are coming from the usual suspects (Esteban, Joxean, David, Alex) and some other people like Pete Finnigan, Mariano Nunez Di Croce, Ali Kumcu and Alexandr Polyakov.
According to an email from Oracle secalert they fixed 7 of my vulnerabilities (tracking numbers: 6980733, 7520291, 9675443, 9675563, 9675681, 9675695, 9675857) but they mapped them to DB05, DB04 and DB02.
The highest database CVSS rating of 6.5 has DB01.
DB02, DB03, DB04 and DB05 are SQL Injection vulnerabilities allowing privilege escalation.
The highest application server CVSS ratings of 9.3 are 2 bugs (AS01, AS02) in Oracle Jinitiator 1.1.8.26 and 1.3.1.27 and affects clients only.
Other interesting information are described in the Metalink note [2] 466757.1. With this CPU it is necessary to recompile ALL Views to fix the [3] “VIEW” problems fixed with Oracle CPU July/October 2007.
Dieser Artikel wurde ausgedruckt ab Alexander Kornbrust Oracle Security Blog: http://blog.red-database-security.com
URL zum Artikel: http://blog.red-database-security.com/2008/01/15/oracle-cpu-january-2008-is-out/
URLs in this post:
[1] Oracle Critical Patch Update (CPU) January 2008: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan20
08.html
[2] 466757.1: http://blog.red-database-security.comhttps://metalink.oracle.com/metalink/plsql/
f?p=130:14:173997832001670216::::p14_database_id,p14_docid,p14_show_header,p14_show_help,p14_black_frame,p14_font:NOT,466757.1,1,1,1,helvetica
[3] “VIEW” problems: http://www.red-database-security.com/advisory/oracle_view_vulnerability.html
Klicken hier zum Drucken.