OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Full-disclosure] 0day Oracle 10g exploit - dbms_aq.enqueue - become DBA

From: Andrea Purificato - bunker (bunkerfastwebnet.it)
Date: Mon Apr 02 2007 - 13:32:34 CDT


On Monday 02 April 2007 20:12, Gadi Evron wrote:

> Not a 0day. Just publicly released exploit code.

You're right, sorry for mistakes. I meant "first public exploit".

> This is:
> 1. Patched.

Yes: CPUJan2007

> 2. Not publicly exploitable.

Permission grant to public between 9.0.1.x and 10.1.0.x (without CPUJan2007).

Thanks for clarification,
--
Andrea "bunker" Purificato
+++++++++++[>++++++>+++++++++++++++++++++++++++++++++>++++
++++++<<<-]>.>++++++++++.>.<----------.>---------.<+++++++.

http://rawlab.mindcreations.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/