Oracle 0 day

From: Andre van Winssen <dreveewee_at_gmail.com>
Date: Fri, 5 Feb 2010 12:30:37 +0100
Message-ID: <9b46ac491002050330xfecb0c5t745198b02ff4749_at_mail.gmail.com>



Hi listmembers,

the exploit code as published on http://blog.red-database-security.com/ by Alex works against 11gR1 and 11gR2 using a database user that only has CREATE SESSION priv.

so production dba's : be warned. Obvious workaround is to revoke EXECUTE privilege from public on package SYS.DBMS_JVM_EXP_PERMS but impact of that revocation on your own database needs to be tested.

the blackhat movie (
https://media.blackhat.com/bh-dc-10/video/Litchfield_David/BlackHat-DC-2010-Litchfield-DefeatSSL-video.mov) is currently unavailable for some reason :-

Regards,
Andre

--
http://www.freelists.org/webpage/oracle-l
Received on Fri Feb 05 2010 - 05:30:37 CST

Original text of this message