Oracle closes 51 security holesBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    Click here for Free IT - Security Resources! | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard - New Version 9 Out Now - Dld 30-day trial! del.icio.us  digg  Furl  NewsVine  Spurl  Blinklist  Ma.gnolia  Reddit  Tailrank  YahooMyWeb 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2008/12/4 23:27:30
2008/12/4 23:27:30
2008/12/4 23:27:30
2008/12/4 23:27:30
2008/12/4 23:27:30
Downloads
RSS / Atom Feeds
Linux Security : Oracle closes 51 security holes
Posted by Max on 2007/1/18 2:30:00 (912 reads)
Linux Security

Oracle made public a periodical patch update on Tuesday containing 51 fixes, one less than initially expected.

The January 2007 update http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html contains security bug fixes that deal with vulnerabilities in an ample range of Oracle enterprise software products including flaws in Oracle Database, Application Server, Enterprise Manager, Identity Management, E-Business Suite, Developer Suite, and the PeopleSoft software packages.


More than half the patches (26 of the 51) involve Oracle's flagship database software products. Nine of these could be exploited without knowing a user name or password, potentially making them far easier to exploit. Of these, eight involve Oracle HTTP Server. The promised, but delayed, security fix also affects Oracle's database software.


The Oracle patch batch also includes 12 new security fixes for Oracle Application Server, eight of which may be remotely exploitable without authentication, as well as seven new security fixes for the Oracle E-Business Suite. Three patches for Oracle PeopleSoft Enterprise PeopleTools, one of which could be remotely exploitable without logging on, and six patches for Oracle Enterprise Manager (five remotely exploitable) complete the unfestive 51.

Secunia reports (http://secunia.com/advisories/23794) that the impact of some of the vulnerabilities is not clear while others might be tied together to gain access to sensitive information, run denial of service attacks, or conduct cross-site scripting and SQL injection attacks.

Oracle has been criticised in the past over the time it takes to develop security patches, and been asked to be more transparent about its security practices. In October, during its last release cycle, Oracle began rating the severity of bugs in its applications according to the Common Vulnerability Scoring System (CVSS), an industry-wide initiative designed to standardise vulnerability rating. Oracle rates this quarter patch batch at 7.0 in a scale from zero to 10, where 10 indicates impending internet meltdown (or some such calamity).

Amichai Shulman, CTO of Israeli database and application security firm Imperva, reckons that some of the vulnerabilities are more severe than Oracle suggests. In particular, he highlighted flaws in Oracle's HTTP server that might be exploited remotely without authentication. "The SSL implementation flaw is the worst of the lot," he added.

A number of the flaws might lend themselves to SQL injections attacks. Exploits would not be difficult for a skilled hacker to craft, Shulman added. Meanwhile, applying the patches would normally involve downtime so it might be some time before enterprises are ready to roll-out fixes.

Long lead times are involved in developing database packages, and this is as true for IBM as it is for Oracle. For this reason releasing Oracle updates on a monthly instead of quarterly basis is unrealistic, according to Shulman.

He added that although Oracle is making some progress in improving its patching process it ought to to be more flexible about the possibility of releasing unscheduled fixes closer to the time when the most severe security flaws are discovered. ®




Other articles
2008/12/4 2:24:49 - Google Chrome Browser to Get Security Extensions
2008/12/4 2:04:47 - Practical Guide for Secure Christmas Shopping by Panda Security
2008/12/1 4:01:09 - GFI Releases the Most Advanced Version of GFI LANguard™
2008/12/1 3:46:23 - New From Symantec : Norton AntiVirus 2009 Gaming Edition
2008/11/26 14:25:35 - NEW! FREE IObit Advanced SystemCare Version 3.0
2008/11/26 14:21:32 - Discretix and MontaVista Linux Release DRM Content Protection
2008/11/23 5:41:27 - High School Musical Songs and Videos Used to Infect Unsuspecting Users
2008/11/23 5:18:40 - Beware Microsoft, Free Anti-Virus Is a Hard Taks ! Warns AVG
2008/11/18 16:16:42 - Beware of Increased Identity Theft on Upcoming Black Friday and Cyber Monday
2008/11/18 16:11:38 - Microsoft Plans New FREE Antimalware Product Codename "Morro"

The comments are owned by the poster. We aren't responsible for their content.