- Alexander Kornbrust Oracle Security Blog - http://blog.red-database-security.com -

Oracle CPU April 2010 is out

Dieser Eintrag stammt von Alexander Kornbrust Am 13 Apr 2010 @ 21:15 In Oracle Security | Kommentarfunktion deaktiviert

Oracle just released the [1] Oracle CPU (and PSU) for April 2010. As mentioned in a [2] previous blog post this CPU contains 7 new security vulnerabilities.  7 new security vulnerability fixes. None of these vulnerabilities are remote exploitable without authentication.

The highest CVSS base score for the Oracle database is 7.5 (Oracle Fusion Middleware). It seems that the Java 0day from David Litchfield is also fixed. But I have to download the Oracle patches to verify that all bugs are fixed.

The following components are affected:

• Change Data Capture
• Core RDBMS
• JavaVM
• Oracle XDB
• RDBMS Security
• XML DB
• Audit

[3] DOAG Expertenseminar

This time all Oracle vulnerabilities are coming from the usual suspects:
Okan Basegmez of DORASEC Consulting; Esteban Martinez Fayo of Application Security, Inc.; Joxean Koret; Alexander Kornbrust of Red Database Security; David Litchfield formerly of NGS Software; Oleg P. of HSC Security Portal; and Alexandr Polyakov of Digital Security.

Oracle has fixed a problem ([4] CVE-2010-0854) I reported in January 2009. It is possible to bypass Oracle Auditing using explain plan. Within the next few days I will release an advisory for this problem.


Dieser Artikel wurde ausgedruckt ab Alexander Kornbrust Oracle Security Blog: http://blog.red-database-security.com

URL zum Artikel: http://blog.red-database-security.com/2010/04/13/oracle-cpu-april-2010-is-out/

URLs in this post:
[1] Oracle CPU (and PSU) for April 2010: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr20
10.html

[2] previous blog: http://blog.red-database-security.com/2010/04/09/oracle-cpu-april-2010-prereleas
e/

[3] Image: http://www.red-database-security.com/doag_expertenseminar.html
[4] CVE-2010-0854: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0854

Klicken hier zum Drucken.