Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 30 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » July 2005 » David Litchfield has released an advisory for the recent CPU 12 April vulnerabilities

[Previous entry: "Oracle have issued a second email with another exploitable vulnerability in 10.1.0.2 in CPU 12APR"] [Next entry: "Is it possible to check whether Oracles CPU update emails are *real*?"]

David Litchfield has released an advisory for the recent CPU 12 April vulnerabilities

July 8th, 2005 by Pete

Post to del.icio.us   Post to Furl   Digg!

I got an email yesterday from Alex to let me know that he had seen the advisory post by David Litchfield to the Bugtraq mailing list. The post is titled "Problems with the Oracle Critical Patch Update for April 2005" and goes on to explain in more detail than Oracle's emails the issues that have been found. He starts by saying he analysed CPU 12 Apr and found that some bugs were not fixed that should have been. The first set of issues are SQL Injection bugs in DBMS_SUBSCRIBE and DBMS_ISUBSCRIBE. The issue is that the CPU Apr 12 patch fails to load the newly fixed Java classes.

The second issue is that the CTXSYS.DRILOAD package on Windows 32 and 64 but for 10.1.0.2 is still vulnerable to exploit. A hacker can gain DBA with this package. This bug is caused by the patch copying the fixed file to the wrong location. If the August 2004 or Jan 2005 patches have been applied then David suggests that the exploit will not work for this version.

Oracle should hold their heads in shame on this one. Surely after finishing a patch fix and before release Oracle would test a patched server to see if it is still vulnerable? Oracle's next quarterly scheduled patch is due on July 12 so let's hope there is some quick re-checking going on behind the scenes!


July 2005
SMTWTFS
     12
3456789
10111213141516
17181920212223
24252627282930
31      

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0


Valid XHTML 1.0!