| Patched Oracle database still at risk, bughunter says |
|
|
| Written by Hans Straat, Thursday, 27 April 2006 | |
|
Oracle's latest update fails to tackle a database flaw that has already been exploited, a security researcher has warned. Last week, the business software maker issued its quarterly Critical Patch Update, addressing more than 30 flaws in its software. However, the update for Oracle 10g Release 2 does not plug a hole that allows published attack code to run, according to a message sent to the Full Disclosure security list on Wednesday by David Litchfield, a researcher at Next Generation Security Software The exploit, released on the Internet last week, isn't for a flaw that Oracle patched, but for a new problem. Initially, experts believed it was for one of the patched vulnerabilities. Intruders could still gain higher privileges on a system via the new flaw in the database's (DBMS) export extension--a component that has been a recurring source of problems, Litchfield wrote. Other versions of 10g may also be affected, Symantec said in an alert to users of its DeepSight intelligence service. |
| < Prev | Next > |
|---|

