Patched Oracle database still at risk, bughunter says Print E-mail
Written by Hans Straat, Thursday, 27 April 2006

Oracle's latest update fails to tackle a database flaw that has already been exploited, a security researcher has warned.

Last week, the business software maker issued its quarterly Critical Patch Update, addressing more than 30 flaws in its software. However, the update for Oracle 10g Release 2 does not plug a hole that allows published attack code to run, according to a message sent to the Full Disclosure security list on Wednesday by David Litchfield, a researcher at Next Generation Security Software

The exploit, released on the Internet last week, isn't for a flaw that Oracle patched, but for a new problem. Initially, experts believed it was for one of the patched vulnerabilities.

Intruders could still gain higher privileges on a system via the new flaw in the database's (DBMS) export extension--a component that has been a recurring source of problems, Litchfield wrote.

Other versions of 10g may also be affected, Symantec said in an alert to users of its DeepSight intelligence service.

read full story

Comments
Add NewSearchRSS
Only registered users can write comments!
 
< Prev   Next >