Skip to main content

Oracle drops a pile of critical patches in 78-update release

posted onJanuary 18, 2012
by l33tdawg

Oracle has released a wave of 78 security updates for its software products all at once, including fixes for a number of vulnerabilities—in products including Oracle Database Server, Solaris, Fusion Middleware, E-Business Suite, and MySQL—that "may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password." While the majority of these bugs don't compromise data security, they could be exploited to crash applications.

The vulnerability in Oracle Database, which affects a number of versions from 10.1 through 11.2, is in the database's listener program—which accepts remote commands from other applications. The listener program has been the source of a number of vulnerabilities, dating back at least ten years. While the vulnerability doesn't reveal data in the core database, it can be used to deny access to the database by other applications. There's also a fix for a vulnerability in the core DBMS in Oracle Database of a less critical nature that is not exploitable without authentication—but "has a significant non-security component."

Solaris also had eight patches released, with some going all the way back to Solaris 8 in scope. One TCP/IP vulnerability (affecting Solaris 9, 10, 11 and Solaris Express) would allow a remote attacker to completely crash the operating system. And a flaw in Solaris' Kerberos implementation, executable with single authentication, could allow a full owning of the system. Other less severe holes patched in Solaris include vulnerabilities in Solaris' RPC services, kernel, and secure shell (SSH) daemon.

Source

Tags

Oracle Security

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th