漏洞信息详情
Oracle Database Server多个未明漏洞
- CNNVD编号:CNNVD-200511-074
- 危害等级: 超危
- CVE编号:
CVE-2005-3438
- 漏洞类型:
缓冲区溢出
- 发布时间:
2005-07-20
- 威胁类型:
远程
- 更新时间:
2005-11-15
- 厂 商:
oracle - 漏洞来源:
Brian CarrSacha Fa… -
漏洞简介
Oracle Database是一款商业性质大型数据库系统。
Oracle Database Server 9i 直到 10.1.0.4.2 存在多个未明漏洞,攻击影响和攻击载体未知。Oracle分别标记为Vuln# (1) DB04 in Change Data Capture; (2) DB06 in Data Guard Logical Standby; (3) DB10 in Locale; (4) DB12 in Materialized Views; (5) DB13 in Objects Extension; (6) DB15 in Oracle Label Security; (7) DB27 in Security, possibly due to a buffer overflow in sys.pbsde.init; and (8) DB28 and (9) DB29 in Workspace Manager.
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333956.1
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333959.1
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333961.1
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333963.1
http://www.peoplesoft.com/corp/en/support/security_index.jsp
参考网址
来源: US-CERTA
名称: TA05-292A
链接:http://www.us-cert.gov/cas/techalerts/TA05-292A.html
来源: US-CERT
名称: VU#449444
链接:http://www.kb.cert.org/vuls/id/449444
来源: US-CERT
名称: VU#210524
链接:http://www.kb.cert.org/vuls/id/210524
来源: www.oracle.com
链接:http://www.oracle.com/technology/deploy/security/pdf/cpuoct2005.html
来源: FULLDISC
名称: 20051020 Exploit Oracle DB27 – CPU Octobre
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2005-October/038061.html
来源: BID
名称: 15134
链接:http://www.securityfocus.com/bid/15134
来源: SECUNIA
名称: 17250