- Alexander Kornbrust Oracle Security Blog - http://blog.red-database-security.com -
6 Advisories (2 from RDS) for Oracle CPU July 2009 posted
Dieser Eintrag stammt von Alexander Kornbrust Am 27 Jul 2009 @ 17:31 In Oracle Security | Kommentarfunktion deaktiviert
I just posted 2 new advisories for the July 2009 CPU from Oracle on my website.
The first advisory ([1] CVE-2009-1021) is about PL/SQL Injection vulnerabilities in the package DBMS_EXPORT_EXTENSION. In July 2006 Oracle fixed already vulnerabilities in this package but the bugfix was not implemented properly.
The second advisory ([2] CVE-2009-1969) is about an information disclosure problem in Oracle audit logs. In some cases these audit logs can contain password hashes.
Last Friday Denis Yurichev released 4 new advisories concerning the TNS Listener in Oracle 10g/11g. All advisories are explained with a proof-of-concept code.
The first and most critical bug (CVSS 9.0 Win/6.5 Linux) advisory ([3] CVE-2009-1020) is remote exploitable but requires an authentication. All databases (9.2.08, 10.1.0.5, 10.2.0.4 and 11.1.0.7) are affected.
The second advisory ([4] CVE-2009-1019) is remote exploitable without authentication. The P.o.C.of Denis creates a denial of service against the database. All databases (9.2.08, 10.1.0.5, 10.2.0.4 and 11.1.0.7) are affected.
The third advisory ([5] CVE-2009-1963) is remote exploitable with authentication. The P.o.C.of Denis creates a denial of service against the database. 11.1.0.7 is affected.
The fourth advisory ([6] CVE-2009-1970), remote exploitable without authentication, is a denial of service vulnerability against the database. Oracle 10.1.0.5, 10.2.0.4 and 11.1.0.6 are affected.
Dieser Artikel wurde ausgedruckt ab Alexander Kornbrust Oracle Security Blog: http://blog.red-database-security.com
URL zum Artikel: http://blog.red-database-security.com/2009/07/27/2-advisories-for-oracle-cpu-july-2009-posted/
URLs in this post:
[1] CVE-2009-1021: http://www.red-database-security.com/advisory/oracle_plsql_injection_dbms_export
_extension.html
[2] CVE-2009-1969: http://www.red-database-security.com/advisory/oracle_password_hash_audit.html
[3] CVE-2009-1020: http://blogs.conus.info/node/23
[4] CVE-2009-1019: http://blogs.conus.info/node/24
[5] CVE-2009-1963: http://blogs.conus.info/node/25
[6] CVE-2009-1970: http://blogs.conus.info/node/26
Klicken hier zum Drucken.