Oracle October Security Update Multiple Vulnerabilities
BID:15134
Info
Oracle October Security Update Multiple Vulnerabilities
| Bugtraq ID: | 15134 |
| Class: | Unknown |
| CVE: |
CVE-2005-0873 CVE-2005-3437 CVE-2005-3438 CVE-2005-3439 CVE-2005-3440 CVE-2005-3441 CVE-2005-3442 CVE-2005-3443 CVE-2005-3444 CVE-2005-3445 CVE-2005-3446 CVE-2005-3447 CVE-2005-3448 CVE-2005-3449 CVE-2005-3450 CVE-2005-3451 CVE-2005-3452 CVE-2005-3453 CVE-2005-3454 CVE-2005-3455 CVE-2005-3456 CVE-2005-3457 CVE-2005-3458 CVE-2005-3459 CVE-2005-3460 CVE-2005-3461 CVE-2005-3462 CVE-2005-3463 CVE-2005-3464 CVE-2005-3465 CVE-2005-3466 CVE-2005-3437 CVE-2005-3438 CVE-2005-3439 CVE-2005-3440 CVE-2005-3441 CVE-2005-3442 CVE-2005-3443 CVE-2005-3444 CVE-2005-3445 CVE-2005-3446 CVE-2005-3447 CVE-2005-3448 CVE-2005-3449 CVE-2005-3450 CVE-2005-3451 CVE-2005-3452 CVE-2005-3453 CVE-2005-3454 CVE-2005-3455 CVE-2005-3456 CVE-2005-3457 CVE-2005-3458 CVE-2005-3459 CVE-2005-3460 CVE-2005-3461 CVE-2005-3462 CVE-2005-3463 CVE-2005-3464 CVE-2005-3465 CVE-2005-3466 CVE-2005-3437 CVE-2005-3438 CVE-2005-3439 CVE-2005-3440 CVE-2005-3441 CVE-2005-3442 CVE-2005-3443 CVE-2005-3444 CVE-2005-3445 CVE-2005-3446 CVE-2005-3447 CVE-2005-3448 CVE-2005-3449 CVE-2005-3450 CVE-2005-3451 CVE-2005-3452 CVE-2005-3453 CVE-2005-3454 CVE-2005-3455 CVE-2005-3456 CVE-2005-3457 CVE-2005-3458 CVE-2005-3459 CVE-2005-3460 CVE-2005-3461 CVE-2005-3462 CVE-2005-3463 CVE-2005-3464 CVE-2005-3465 CVE-2005-3466 CVE-2005-3437 CVE-2005-3438 CVE-2005-3439 CVE-2005-3440 CVE-2005-3441 CVE-2005-3442 CVE-2005-3443 CVE-2005-3444 CVE-2005-3445 CVE-2005-3446 CVE-2005-3447 CVE-2005-3448 CVE-2005-3449 CVE-2005-3450 CVE-2005-3451 CVE-2005-3452 CVE-2005-3453 CVE-2005-3454 CVE-2005-3455 CVE-2005-3456 CVE-2005-3457 CVE-2005-3458 CVE-2005-3459 CVE-2005-3460 CVE-2005-3461 CVE-2005-3462 CVE-2005-3463 CVE-2005-3464 CVE-2005-3465 CVE-2005-3466 CVE-2005-3437 CVE-2005-3438 CVE-2005-3439 CVE-2005-3440 CVE-2005-3441 CVE-2005-3442 CVE-2005-3443 CVE-2005-3444 CVE-2005-3445 CVE-2005-3446 CVE-2005-3447 CVE-2005-3448 CVE-2005-3449 CVE-2005-3450 CVE-2005-3451 CVE-2005-3452 CVE-2005-3453 CVE-2005-3454 CVE-2005-3455 CVE-2005-3456 CVE-2005-3457 CVE-2005-3458 CVE-2005-3459 CVE-2005-3460 CVE-2005-3461 CVE-2005-3462 CVE-2005-3463 CVE-2005-3464 CVE-2005-3465 CVE-2005-3466 CVE-2005-3437 CVE-2005-3438 CVE-2005-3439 CVE-2005-3440 CVE-2005-3441 CVE-2005-3442 CVE-2005-3443 CVE-2005-3444 CVE-2005-3445 CVE-2005-3446 CVE-2005-3447 CVE-2005-3448 CVE-2005-3449 CVE-2005-3450 CVE-2005-3451 CVE-2005-3452 CVE-2005-3453 CVE-2005-3454 CVE-2005-3455 CVE-2005-3456 CVE-2005-3457 CVE-2005-3458 CVE-2005-3459 CVE-2005-3460 CVE-2005-3461 CVE-2005-3462 CVE-2005-3463 CVE-2005-3464 CVE-2005-3465 CVE-2005-3466 CVE-2005-3437 CVE-2005-3438 CVE-2005-3439 CVE-2005-3440 CVE-2005-3441 CVE-2005-3442 CVE-2005-3443 CVE-2005-3444 CVE-2005-3445 CVE-2005-3446 CVE-2005-3447 CVE-2005-3448 CVE-2005-3449 CVE-2005-3450 CVE-2005-3451 CVE-2005-3452 CVE-2005-3453 CVE-2005-3454 CVE-2005-3455 CVE-2005-3456 CVE-2005-3457 CVE-2005-3458 CVE-2005-3459 CVE-2005-3460 CVE-2005-3461 CVE-2005-3462 CVE-2005-3463 CVE-2005-3464 CVE-2005-3465 CVE-2005-3466 CVE-2005-3437 CVE-2005-3438 CVE-2005-3439 CVE-2005-3440 CVE-2005-3441 CVE-2005-3442 CVE-2005-3443 CVE-2005-3444 CVE-2005-3445 CVE-2005-3446 CVE-2005-3447 CVE-2005-3448 CVE-2005-3449 CVE-2005-3450 CVE-2005-3451 CVE-2005-3452 CVE-2005-3453 CVE-2005-3454 CVE-2005-3455 CVE-2005-3456 CVE-2005-3457 CVE-2005-3458 CVE-2005-3459 CVE-2005-3460 CVE-2005-3461 CVE-2005-3462 CVE-2005-3463 CVE-2005-3464 CVE-2005-3465 CVE-2005-3466 CVE-2005-3437 CVE-2005-3438 CVE-2005-3439 CVE-2005-3440 CVE-2005-3441 CVE-2005-3442 CVE-2005-3443 CVE-2005-3444 CVE-2005-3445 CVE-2005-3446 CVE-2005-3447 CVE-2005-3448 CVE-2005-3449 CVE-2005-3450 CVE-2005-3451 CVE-2005-3452 CVE-2005-3453 CVE-2005-3454 CVE-2005-3455 CVE-2005-3456 CVE-2005-3457 CVE-2005-3458 CVE-2005-3459 CVE-2005-3460 CVE-2005-3461 CVE-2005-3462 CVE-2005-3463 CVE-2005-3464 CVE-2005-3465 CVE-2005-3466 CVE-2005-3437 CVE-2005-3438 CVE-2005-3439 CVE-2005-3440 CVE-2005-3441 CVE-2005-3442 CVE-2005-3443 CVE-2005-3444 CVE-2005-3445 CVE-2005-3446 CVE-2005-3447 CVE-2005-3448 CVE-2005-3449 CVE-2005-3450 CVE-2005-3451 CVE-2005-3452 CVE-2005-3453 CVE-2005-3454 CVE-2005-3455 CVE-2005-3456 CVE-2005-3457 CVE-2005-3458 CVE-2005-3459 CVE-2005-3460 CVE-2005-3461 CVE-2005-3462 CVE-2005-3463 CVE-2005-3464 CVE-2005-3465 CVE-2005-3466 CVE-2005-3437 CVE-2005-3438 CVE-2005-3439 CVE-2005-3440 CVE-2005-3441 CVE-2005-3442 CVE-2005-3443 CVE-2005-3444 CVE-2005-3445 CVE-2005-3446 CVE-2005-3447 CVE-2005-3448 CVE-2005-3449 CVE-2005-3450 CVE-2005-3451 CVE-2005-3452 CVE-2005-3453 CVE-2005-3454 CVE-2005-3455 CVE-2005-3456 CVE-2005-3457 CVE-2005-3458 CVE-2005-3459 CVE-2005-3460 CVE-2005-3461 CVE-2005-3462 CVE-2005-3463 CVE-2005-3464 CVE-2005-3465 CVE-2005-3466 CVE-2005-0873 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 18 2005 12:00AM |
| Updated: | Oct 23 2012 03:40PM |
| Credit: | The following people are credited for the discovery of vulnerabilities listed in the Critical Patch Update: Brian Carr; Sacha Faust of S.P.I. Dynamics, Inc.; Esteban Martínez Fayó of Application Security, Inc.; Alexander Kornbrust of Red Database Securi |
| Vulnerable: |
PeopleSoft PeopleTools 8.46.3 PeopleSoft PeopleTools 8.45.5 PeopleSoft PeopleTools 8.43 PeopleSoft PeopleTools 8.42 PeopleSoft PeopleTools 8.41 PeopleSoft PeopleTools 8.40 PeopleSoft PeopleTools 8.20.7 PeopleSoft PeopleTools 8.20 PeopleSoft PeopleTools 8.19 PeopleSoft PeopleTools 8.18 PeopleSoft PeopleTools 8.17 PeopleSoft PeopleTools 8.16 PeopleSoft PeopleTools 8.15 PeopleSoft PeopleTools 8.14 PeopleSoft PeopleTools 8.13 PeopleSoft PeopleTools 8.12 PeopleSoft PeopleTools 8.11 PeopleSoft PeopleTools 8.10 PeopleSoft CRM 8.9 PeopleSoft CRM 8.8.1 Oracle Workflow 11.5.9 .5 Oracle Workflow 11.5.1 Oracle PeopleSoft Enterprise Customer Relationship Manage 8.9 Oracle Oracle9i Standard Edition 9.2 .6 Oracle Oracle9i Standard Edition 9.2 .0.5 Oracle Oracle9i Standard Edition 9.0.1 .5 FIPS Oracle Oracle9i Standard Edition 9.0.1 .5 Oracle Oracle9i Standard Edition 9.0.1 .4 Oracle Oracle9i Personal Edition 9.2 .7 Oracle Oracle9i Personal Edition 9.2 .6 Oracle Oracle9i Personal Edition 9.2 .0.5 Oracle Oracle9i Personal Edition 9.0.1 .5 FIPS Oracle Oracle9i Personal Edition 9.0.1 .5 Oracle Oracle9i Personal Edition 9.0.1 .4 Oracle Oracle9i Enterprise Edition 9.2 .7.0 Oracle Oracle9i Enterprise Edition 9.2 .6.0 Oracle Oracle9i Enterprise Edition 9.2 .0.5 Oracle Oracle9i Enterprise Edition 9.0.1 .5 FIPS Oracle Oracle9i Enterprise Edition 9.0.1 .5 Oracle Oracle9i Enterprise Edition 9.0.1 .4 Oracle Oracle9i Application Server Web Cache 9.0.3 .1 Oracle Oracle9i Application Server Web Cache 9.0.2 .3 Oracle Oracle9i Application Server 9.2 .0.7 Oracle Oracle9i Application Server 9.2 .0.6 Oracle Oracle9i Application Server 9.0.3 .1 Oracle Oracle9i Application Server 9.0.2 .3 Oracle Oracle8i Standard Edition 8.1.7 .4 Oracle Oracle8i Standard Edition 8.0.6 .3 Oracle Oracle8i Standard Edition 8.0.6 Oracle Oracle8i Enterprise Edition 8.1.7 .4.0 Oracle Oracle8 8.1.7 .4 Oracle Oracle8 8.0.6 .3 Oracle Oracle8 8.0.6 Oracle Oracle10g Standard Edition 10.1 .4.2 Oracle Oracle10g Standard Edition 10.1 .0.4 Oracle Oracle10g Standard Edition 10.1 .0.3.1 Oracle Oracle10g Standard Edition 10.1 .0.3 Oracle Oracle10g Standard Edition 10.1 .0.2 Oracle Oracle10g Personal Edition 10.1 .0.4 Oracle Oracle10g Personal Edition 10.1 .0.3.1 Oracle Oracle10g Personal Edition 10.1 .0.3 Oracle Oracle10g Personal Edition 10.1 .0.2 Oracle Oracle10g Enterprise Edition 10.1 .4.2 Oracle Oracle10g Enterprise Edition 10.1 .0.4 Oracle Oracle10g Enterprise Edition 10.1 .0.3.1 Oracle Oracle10g Enterprise Edition 10.1 .0.3 Oracle Oracle10g Enterprise Edition 10.1 .0.2 Oracle Oracle10g Application Server 10.1.2 Oracle Oracle10g Application Server 10.1 .0.4 Oracle Oracle10g Application Server 10.1 .0.3.1 Oracle Oracle10g Application Server 10.1 .0.3 Oracle Oracle10g Application Server 10.1 .0.2 Oracle Oracle 9i Application Server Release 1 1.0.2 .2 Oracle JD Edwards EnterpriseOne 8.95 _B1 Oracle JD Edwards EnterpriseOne 8.94 _Q1 Oracle JD Edwards EnterpriseOne SP23_K1 Oracle Enterprise Manager Grid Control 10g 10.1 .4 Oracle Enterprise Manager Grid Control 10g 10.1 .3 Oracle Enterprise Manager Database Control 10g 10.1 .0.4 Oracle Enterprise Manager Database Control 10g 10.1 .0.3 Oracle Enterprise Manager Application Server Control 9.0.4 .2 Oracle Enterprise Manager Application Server Control 9.0.4 .1 Oracle Enterprise Manager 9.0.4 .1 Oracle E-Business Suite 11i 11.5.10 Oracle E-Business Suite 11i 11.5.9 Oracle E-Business Suite 11i 11.5.8 Oracle E-Business Suite 11i 11.5.7 Oracle E-Business Suite 11i 11.5.6 Oracle E-Business Suite 11i 11.5.5 Oracle E-Business Suite 11i 11.5.4 Oracle E-Business Suite 11i 11.5.3 Oracle E-Business Suite 11i 11.5.2 Oracle E-Business Suite 11i 11.5.1 Oracle E-Business Suite 11i 11.5 Oracle E-Business Suite 11.0 Oracle Developer Suite 10.1.2 Oracle Developer Suite 9.0.4 .2 Oracle Developer Suite 9.0.4 .1 Oracle Developer Suite 9.0.2 .1 Oracle Collaboration Suite Release 2 9.0.4 .2 Oracle Collaboration Suite Release 1 10.1.1 Oracle Collaboration Suite Release 1 Oracle Clinical 4.5.1 Oracle Clinical 4.5 Oracle Application Server Release 2 10.1.2 .0.2 Oracle Application Server Release 2 10.1.2 .0.1 Oracle Application Server Release 2 10.1.2 .0.0 Oracle Application Server Release 2 9.0.2 .3 Oracle Application Server Release 2 9.0.2 .1 Oracle Application Server 10g 9.0.4 .2 Oracle Application Server 10g 9.0.4 .1 Oracle Application Server 10g 9.0.4 Oracle Application Server 10.1.2 .0.2 HP HP-UX 11.23 HP HP-UX 11.11 HP HP-UX B.11.23 HP HP-UX B.11.11 |
| Not Vulnerable: | |
Discussion
Oracle October Security Update Multiple Vulnerabilities
Various Oracle Database Server, Oracle Enterprise Manager, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, and Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne are affected by multiple vulnerabilities.
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats.
Oracle has released a Critical Patch Update advisory for October 2005 to address these vulnerabilities. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier, unsupported releases are likely to be affected by the issues as well.
Specific details regarding these vulnerabilities are not currently available.
This record will be updated and split into individual BIDs for each issue as further information is disclosed.
Various Oracle Database Server, Oracle Enterprise Manager, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, and Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne are affected by multiple vulnerabilities.
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats.
Oracle has released a Critical Patch Update advisory for October 2005 to address these vulnerabilities. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier, unsupported releases are likely to be affected by the issues as well.
Specific details regarding these vulnerabilities are not currently available.
This record will be updated and split into individual BIDs for each issue as further information is disclosed.
Exploit / POC
Oracle October Security Update Multiple Vulnerabilities
An exploit would not be required for some of these issues such as the SQL injection vulnerabilities. Other issues would likely require exploit code.
The following proof of concept code provided by <[email protected]> is available for DB27:
SQL> exec
sys.pbsde.init('AA',TRUE,'MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_A
NN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MA
RY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSO
N_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON',NULL);
BEGIN
sys.pbsde.init('AA',TRUE,'MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_A
NN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MA
RY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSO
N_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON',NULL); END;
---
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
An exploit would not be required for some of these issues such as the SQL injection vulnerabilities. Other issues would likely require exploit code.
The following proof of concept code provided by <[email protected]> is available for DB27:
SQL> exec
sys.pbsde.init('AA',TRUE,'MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_A
NN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MA
RY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSO
N_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON',NULL);
BEGIN
sys.pbsde.init('AA',TRUE,'MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_A
NN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MA
RY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSO
N_MARY_ANN_DAVIDSON_MARY_ANN_DAVIDSON',NULL); END;
---
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Oracle October Security Update Multiple Vulnerabilities
Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - October 2005) to address these issues. Information regarding obtaining and applying appropriate patches can be found in the referenced Oracle Critical Patch Update.
Pre-installation notes for Oracle Database Server can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333956.1
Pre-installation notes for Oracle Application Server can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333959.1
Pre-installation notes for Oracle Collaboration Suite can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333961.1
Pre-installation notes for Oracle E-Business Suite and Applications can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333963.1
Pre-installation notes for Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne can be found at the following location:
http://www.peoplesoft.com/corp/en/support/security_index.jsp
A message from "David Litchfield" <[email protected]> is available that states that some of the vulnerabilities in Oracle Critical Patch Update - October 2005 may not have been successfully fixed by Oracle. Users of affected packages should refer to the referenced message, and contact their vendor for further information on the status of fixes.
HP has released advisory HPSBMA01235 (SSRT051055 rev.0 - HP Oracle for OpenView (OfO) Critical Patch Update October 2005) to identify vulnerable HP packages and fixes. HP advises users of Oracle for Openview who have support contracts with Oracle to obtain Critical Patch Update - October 2005 from Oracle. Users of Oracle for Openview who have support contracts with HP can contact HP for fixes. Please see the referenced advisory for more information.
A message from "NGSSoftware Insight Security Research" <[email protected]> (Oracle October 2005 CPU Problems) states that there is a flaw in the fix for the CTXSYS component of Oracle 8.1.7.4 on all platforms. Please see the referenced message for further details on this issue.
Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - October 2005) to address these issues. Information regarding obtaining and applying appropriate patches can be found in the referenced Oracle Critical Patch Update.
Pre-installation notes for Oracle Database Server can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333956.1
Pre-installation notes for Oracle Application Server can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333959.1
Pre-installation notes for Oracle Collaboration Suite can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333961.1
Pre-installation notes for Oracle E-Business Suite and Applications can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=333963.1
Pre-installation notes for Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne can be found at the following location:
http://www.peoplesoft.com/corp/en/support/security_index.jsp
A message from "David Litchfield" <[email protected]> is available that states that some of the vulnerabilities in Oracle Critical Patch Update - October 2005 may not have been successfully fixed by Oracle. Users of affected packages should refer to the referenced message, and contact their vendor for further information on the status of fixes.
HP has released advisory HPSBMA01235 (SSRT051055 rev.0 - HP Oracle for OpenView (OfO) Critical Patch Update October 2005) to identify vulnerable HP packages and fixes. HP advises users of Oracle for Openview who have support contracts with Oracle to obtain Critical Patch Update - October 2005 from Oracle. Users of Oracle for Openview who have support contracts with HP can contact HP for fixes. Please see the referenced advisory for more information.
A message from "NGSSoftware Insight Security Research" <[email protected]> (Oracle October 2005 CPU Problems) states that there is a flaw in the fix for the CTXSYS component of Oracle 8.1.7.4 on all platforms. Please see the referenced message for further details on this issue.
References
Oracle October Security Update Multiple Vulnerabilities
References:
References:
- Critical Patch Update - October 2005 (Oracle)
- Details Oracle Critical Patch Update October 2005 (Red-Database-Security GmbH)
- Oracle Critical Patch Update - October 2005 - E-Business Suite Impact (Integrigy Security)
- Oracle Homepage (Oracle)
- VU#171364 - Oracle Application Server SQL*ReportWriter vulnerability (US-CERT)
- VU#376756 - Oracle Application Server Internet Directory vulnerability (US-CERT)
- VU#512716 - Oracle Application Server Web Cache vulnerability (US-CERT)
- VU#890940 - Oracle HTTP Server vulnerability (US-CERT)
- Oracle DBMS_ASSERT and the October 2005 CPU ("NGSSoftware Insight Security Research"
) - Revision: Multiple Critical and High Vulnerabilities in Oracle Database Server ("David Litchfield"
)