Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 23 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » July 2005 » Sun has released an alert notification (15 July 2005) about multiple security vulnerabilities in Oracle affecting SunMC

[Previous entry: "A Russian language news article about unfixed Oracle security bugs disclosure"] [Next entry: "Oracle dragging heels on unfixed flaws, researcher says"]

Sun has released an alert notification (15 July 2005) about multiple security vulnerabilities in Oracle affecting SunMC

July 19th, 2005 by Pete

Post to del.icio.us   Post to Furl   Digg!

Sun has released an alert notification (Sun Alert ID 101782) dated 15 July 2005 and titled "Mulitple Security Vulnerabilities in Oracle Affect SunMC" - The synopsis states that unprivileged local or remote users can execute arbitary code on Solaris systems which have installed and enabled Sun Management Center (SunMC). The SunMC software runs typically as the user "smcorau" which is unprivileged but it uses the Oracle listener. Therefore it is affected by multiple listener vulnerabilities in Oracle Alert #68. This affects SunMC 3.5 on Solaris 8,9 and 10 that have not had Sun patch 118829-04 applied.

Sun recommends installing patch 118829-04 or later and also installing Oracle's latest Critical Patch Update.

Why release a note now about bugs in Alert #68? - This could be symptomatic of a bigger issue. How many companies use Oracle because another supplier uses it and its part of some other software? If the supplier assumes the person running it has patched or vice versa - then how many Oracle systems are out there not patched?


July 2005
SMTWTFS
     12
3456789
10111213141516
17181920212223
24252627282930
31      

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0


Valid XHTML 1.0!