Sie befinden sich in den Archiven der Kategorie CPUOct2008.
| M | D | M | D | F | S | S |
|---|---|---|---|---|---|---|
| « Dez | ||||||
| 1 | 2 | 3 | 4 | |||
| 5 | 6 | 7 | 8 | 9 | 10 | 11 |
| 12 | 13 | 14 | 15 | 16 | 17 | 18 |
| 19 | 20 | 21 | 22 | 23 | 24 | 25 |
| 26 | 27 | 28 | 29 | 30 | 31 | |
- 10.2.0.4 (1)
- 11g (4)
- Allgemein (12)
- BEA (1)
- checkpwd (4)
- CPUApr2008 (3)
- CPUJan2008 (2)
- CPUJul2007 (3)
- CPUOct2007 (1)
- CPUOct2008 (1)
- Data Vault (1)
- Database Vault (2)
- David Litchfield (5)
- DOAG (1)
- Exploit (4)
- Forensics (4)
- Inguma (3)
- MacOS (1)
- Mary Ann (1)
- Oracle (2)
- Oracle Security (52)
- passwords (5)
- Podcast (1)
- rootkits (1)
- Security (9)
- Security Book (1)
- Sentrigo (2)
- software (2)
- Source Code Analysis (1)
- source code audit (3)
- SQL Injection (4)
- Tools (2)
- Trainings (1)
- 30 Dez 2008: Inguma 0.1.0 (R1) released
- 24 Dez 2008: Merry Christmas
- 14 Dez 2008: New version of cain with support for 11g passwords
- 8 Dez 2008: MD5 Bruteforcer - BarsWF
- 7 Dez 2008: GSAuditor - Fastest Oracle 11g password cracker (AFAIK)
- 5 Dez 2008: DOAG 2008 is over
- 27 Nov 2008: David Litchfield has published a whitepaper on Oracle forensics
- 21 Nov 2008: Oracle Database Vault Privilege Escalation Exploit published
- 14 Okt 2008: Oracle Critical Patch Update October 2008 is out
- 20 Aug 2008: New Oracle bugs and BSQL Hacker
Archiv der Kategorie CPUOct2008
Oracle Critical Patch Update October 2008 is out
14 Okt 2008 von Alexander Kornbrust.
Oracle just released the CPU for October 2008. This time Oracle fixed 36 security bugs across all products. Oracle recommends to apply this CPU with the following words
“Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply fixes as soon as possible.”
The credits are going to the usual suspects: Esteban, Joxean, Pete, Slavik, Amichai plus a few new people like Chris Valasek, Jack Kanter, Tony Fogarty, Guy.
Oracle fixed 4 of my vulnerabilities with this CPU. Some of my issues were reported in 2005…
- SQL INJECTION IN UPGRADE SCRIPT EXFEAPVS.SQL (CVE-2008-3980)
- OLAP_USER HAS CREATE PUBLIC SYNONYM PRIVILEGE (CVE-2008-2624)
- jdeveloper: plaintext password in IDEConnections.xml (CVE-2008-2588)
- SHUTDOWN ANY UNPROTECTED TNS LISTENER VIA REPORTS SERVLET (CVE-2008-2619)
I will release advisories within the next few days.
Geschrieben in CPUOct2008, Oracle Security | Keine Kommentare »