Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 15 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » January 2006 » Alex has produced a detailed analysis of the Jan 2006 CPU

[Previous entry: "The CPU Jan 2006 patch for HP/UX Application Server is empty"] [Next entry: "Duncan Harris speaks on Oracle Security"]

Alex has produced a detailed analysis of the Jan 2006 CPU

January 22nd, 2006 by Pete

Post to del.icio.us   Post to Furl   Digg!

Alex has created a great analysis of the January 2006 Critical Patch Update (CPU Jan 2006). This page is titled "Details Oracle Critical Patch Update January 2006 - V1.06". This paper details all of the packages and functions/procedures that are vulnerable and all parameters where relevant. This section includes a lot of detailed information. The next section includes a mapping of security vulnerabilities in Oracle features and components. Then there is a section mapping oracle vulnerability numbers with vulnerability types and affected versions. Alex also details the very simple password checker also released with this patch that is intended to be used to check for the default users that are mentioned in the recent Oracle worm. A much better default password checker is available on this site that checks for a much larger list of accounts.

Alex has advised me that this is a living document and will be updated as new information becomes available.


January 2006
SMTWTFS
1234567
891011121314
15161718192021
22232425262728
293031    

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0


Valid XHTML 1.0!