Release date:
Updated on:
Affected Systems:
Oracle Database 11.2.0.1
Oracle Database 11.1.0.7
Oracle Database 10.2.0.4
Oracle Database 10.2.0.3
Oracle Database 10.1.0.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 43935
Cve id: CVE-2010-2419
Oracle is a large commercial database system.
Oracle's custom SecurityManager relies on tags of special objects to determine whether privileged calls are successful. Because of a competitive condition, Authenticated Users can bypass sandbox restrictions to execute Java code.
<* Source: Sami Koivu
Link: http://secunia.com/advisories/41815/
Http://marc.info /? L = full-disclosure & m = 128692160118293 & q = p3
Http://www.us-cert.gov/cas/techalerts/TA10-287A.html
Http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Oracle
------
Oracle has released a Security Bulletin (cpuoct2010) and corresponding patches for this:
Cpuoct2010: Oracle Critical Patch Update Advisory-October 2010
Link: http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html