|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Mon Feb 08 2010 - 19:11:09 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
----------------------------------------------------------------------
Secunia integrated with Microsoft WSUS
http://secunia.com/blog/71/
----------------------------------------------------------------------
TITLE:
Oracle Database Two Security Issues
SECUNIA ADVISORY ID:
SA38353
VERIFY ADVISORY:
http://secunia.com/advisories/38353/
DESCRIPTION:
David Litchfield has reported two security issues in Oracle Database,
which can be exploited by malicious users to gain escalated privileges
and compromise a vulnerable system.
1) Access to procedures within the "DBMS_JVM_EXP_PERMS" package is
not restricted, which can be exploited to modify the Java policy
table via the "IMPORT_JVM_PERMS" procedure.
This can be exploited to e.g. execute arbitrary operating system
commands.
2) An error in the argument handling of the
"DBMS_JAVA.SET_OUTPUT_TO_JAVA" procedure can be exploited to execute
SQL commands as the SYS user.
This can be exploited to gain DBA user privileges.
NOTE: Successful exploitation allows bypassing Oracle Label Security.
SOLUTION:
Grant only trusted users access to the application.
PROVIDED AND/OR DISCOVERED BY:
David Litchfield
ORIGINAL ADVISORY:
https://media.blackhat.com/bh-dc-10/video/Litchfield_David/BlackHat-DC-2010-Litchfield-Oracle11g-video.m4v
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]