[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
SV: [Full-Disclosure] [SHATTER Team Security Alert] Multiple vulnerabilities in Oracle Database Server
- To: "xbud" <xbud@xxxxxxxxxxx>, <full-disclosure@xxxxxxxxxxxxxxxx>, "Mark Shirley" <mshirley@xxxxxxxxx>
- Subject: SV: [Full-Disclosure] [SHATTER Team Security Alert] Multiple vulnerabilities in Oracle Database Server
- From: "Peter Kruse" <kruse@xxxxxxxxxxxxxxxx>
- Date: Sat, 4 Sep 2004 00:13:03 +0200
Hi,
>Actually this sounds like someone stole Litchfield's research -
>but what do I
>know. Just seems like too much coincidence since his last talk dealt with
>procedure based vulns.
No, these are separate issues.
This is a coordinated update that fixes multiple vulnerabilities in Oracle.
Details from NGSSoftware won't be disclosed until after 3 months. However,
the advisory publiced by Application Security Inc. contains sufficient data
that could be abused to start exploiting Oracle databases immediately.
Kind regards
Peter Kruse
http://www.csis.dk
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html