<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.1" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Kommentare zu: First exploits for CPUJan2008 published</title>
	<link>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/</link>
	<description>Oracle Security</description>
	<pubDate>Thu, 17 May 2012 00:00:51 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.1</generator>

	<item>
		<title>Von: Log Buffer #83: a Carnival of the Vanities for DBAs</title>
		<link>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-7308</link>
		<author>Log Buffer #83: a Carnival of the Vanities for DBAs</author>
		<pubDate>Fri, 20 Feb 2009 22:18:32 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-7308</guid>
		<description>[...] Staying with Oracle for the moment, Red Database Security&#8217;s blog reports on the First exploits for January&#8217;s CPU. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Staying with Oracle for the moment, Red Database Security&#8217;s blog reports on the First exploits for January&#8217;s CPU. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Joxean Koret</title>
		<link>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-5059</link>
		<author>Joxean Koret</author>
		<pubDate>Fri, 01 Feb 2008 21:14:04 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-5059</guid>
		<description>Sorry for the typo: 

&#62;Many of these were reported to 3rd parties (iDefense and ZDI).

Many "others" were reported to 3rd parties.

Joxean Koret</description>
		<content:encoded><![CDATA[<p>Sorry for the typo: </p>
<p>&gt;Many of these were reported to 3rd parties (iDefense and ZDI).</p>
<p>Many &#8220;others&#8221; were reported to 3rd parties.</p>
<p>Joxean Koret</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Joxean Koret</title>
		<link>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-5057</link>
		<author>Joxean Koret</author>
		<pubDate>Fri, 01 Feb 2008 21:12:08 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-5057</guid>
		<description>Hi Alex,

I have 23 currently unfixed flaws in Oracle Database (taken, as you, from the secalert report). But that number only reflects the total vulnerabilities I reported directly. Many of these were reported to 3rd parties (iDefense and ZDI).

Joxean Koret</description>
		<content:encoded><![CDATA[<p>Hi Alex,</p>
<p>I have 23 currently unfixed flaws in Oracle Database (taken, as you, from the secalert report). But that number only reflects the total vulnerabilities I reported directly. Many of these were reported to 3rd parties (iDefense and ZDI).</p>
<p>Joxean Koret</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Alexander Kornbrust</title>
		<link>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-5052</link>
		<author>Alexander Kornbrust</author>
		<pubDate>Fri, 01 Feb 2008 16:11:41 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-5052</guid>
		<description>Joxean and Alexandr

How many open vulnerabilities do you have in the Oracle database at the moment (if this information is not a secret)? 

We have only 32 open vulnerabilities in the database (taken from the January report from secalert).


Alexander</description>
		<content:encoded><![CDATA[<p>Joxean and Alexandr</p>
<p>How many open vulnerabilities do you have in the Oracle database at the moment (if this information is not a secret)? </p>
<p>We have only 32 open vulnerabilities in the database (taken from the January report from secalert).</p>
<p>Alexander</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Alexander Kornbrust</title>
		<link>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-5051</link>
		<author>Alexander Kornbrust</author>
		<pubDate>Fri, 01 Feb 2008 16:06:10 +0000</pubDate>
		<guid>http://blog.red-database-security.com/2008/01/31/first-exploits-for-cpujan2008-published/#comment-5051</guid>
		<description>Hi Alexandr,

sorry I missed the forth exploit. I did not saw that your exploit was different from the one published a few months ago on bugtraq. The exploit was looking so similar but another procedure was affected.

--

It's not unusual that different researchers are finding / reporting the same vulnerabilities. In this case it seems that Joxean found the bugs already 2005/2006.</description>
		<content:encoded><![CDATA[<p>Hi Alexandr,</p>
<p>sorry I missed the forth exploit. I did not saw that your exploit was different from the one published a few months ago on bugtraq. The exploit was looking so similar but another procedure was affected.</p>
<p>&#8211;</p>
<p>It&#8217;s not unusual that different researchers are finding / reporting the same vulnerabilities. In this case it seems that Joxean found the bugs already 2005/2006.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

