Oracle January Security Update Multiple Vulnerabilities

BID:16287

Info

Oracle January Security Update Multiple Vulnerabilities

Bugtraq ID: 16287
Class: Unknown
CVE: CVE-2006-0283
CVE-2006-0270
CVE-2006-0265
CVE-2005-2378
CVE-2005-2371
CVE-2005-2093
CVE-2005-0873
Remote: Yes
Local: Yes
Published: Jan 17 2006 12:00AM
Updated: Feb 26 2007 07:26PM
Credit: Some of these issues were discovered by Red-Database-Security and NGSSoftware. Esteban Martinez Fayo discovered the XDB.DBMS_XMLSCHEMA buffer overflow issue. The rest of these issues were disclosed by the vendor.
Vulnerable: PeopleSoft Enterprise Portal 8.9
PeopleSoft Enterprise Portal 8.8
PeopleSoft Enterprise Portal 8.4
Oracle Workflow 11.5.9 .5
Oracle Workflow 11.5.1
Oracle Oracle9i Standard Edition 9.2 .7
Oracle Oracle9i Standard Edition 9.2 .6
Oracle Oracle9i Enterprise Edition 9.0.1 .5 FIPS
Oracle Oracle9i Enterprise Edition 9.0.1 .5
Oracle Oracle9i Enterprise Edition 9.0.1 .4
Oracle Oracle9i Application Server 1.0.2 .2
Oracle Oracle8i Standard Edition 8.1.7 .4
Oracle Oracle8i Standard Edition 8.1.7 .4
Oracle Oracle8i Standard Edition 8.0.6 .3
Oracle Oracle8i Standard Edition 8.0.6
Oracle Oracle8i Enterprise Edition 8.1.7 .4.0
Oracle Oracle8 8.1.7 .4
Oracle Oracle8 8.0.6 .3
Oracle Oracle8 8.0.6
Oracle Oracle10g Standard Edition 10.2 .1
Oracle Oracle10g Standard Edition 10.1 .4.2
Oracle Oracle10g Standard Edition 10.1 .0.5
Oracle Oracle10g Standard Edition 10.1 .0.4
Oracle Oracle10g Standard Edition 10.1 .0.3
Oracle Oracle10g Personal Edition 10.1 .0.4
Oracle Oracle10g Personal Edition 10.1 .0.3
Oracle Oracle10g Enterprise Edition 10.1 .0.4
Oracle Oracle10g Enterprise Edition 10.1 .0.3
Oracle Oracle10g Application Server 10.1.2 .1.0
Oracle Oracle10g Application Server 10.1.2 .0.2
Oracle Oracle10g Application Server 10.1.2 .0.1
Oracle Oracle10g Application Server 10.1.2
Oracle Oracle10g Application Server 9.0.4 .2
Oracle Oracle10g Application Server 9.0.4 .1
Oracle Oracle 9i Application Server Release 1 1.0.2 .2
Oracle JD Edwards EnterpriseOne 8.95 _F1
Oracle JD Edwards EnterpriseOne SP23_L1
Oracle Enterprise Manager Grid Control 10g 10.1 .4
Oracle Enterprise Manager Grid Control 10g 10.1 .3
Oracle E-Business Suite 11i 11.5.10
Oracle E-Business Suite 11i 11.5.9
Oracle E-Business Suite 11i 11.5.8
Oracle E-Business Suite 11i 11.5.7
Oracle E-Business Suite 11i 11.5.6
Oracle E-Business Suite 11i 11.5.5
Oracle E-Business Suite 11i 11.5.4
Oracle E-Business Suite 11i 11.5.3
Oracle E-Business Suite 11i 11.5.2
Oracle E-Business Suite 11i 11.5.1
Oracle Developer Suite 10.1.2
Oracle Developer Suite 9.0.4 .2
Oracle Developer Suite 9.0.4 .1
Oracle Developer Suite 9.0.2 .1
Oracle Collaboration Suite Release 2 9.0.4 .2
Oracle Collaboration Suite Release 1 10.1.2
Oracle Collaboration Suite Release 1 10.1.1
Oracle Collaboration Suite Release 1
Oracle Application Server Release 2 10.1.2 .0.2
Oracle Application Server Release 2 10.1.2 .0.1
Oracle Application Server Release 2 10.1.2 .0.0
Oracle Application Server 10g 10.1.2
Oracle Application Server 10g 9.0.4 .2
Oracle Application Server 10g 9.0.4 .1
Oracle Application Server 10g 9.0.4
HP Oracle for OpenView 9.1.1
HP Oracle for OpenView 8.1.7
HP Oracle for OpenView 9.2
Not Vulnerable:

Discussion

Oracle January Security Update Multiple Vulnerabilities

Various Oracle products -- Oracle Database Server, Oracle Enterprise Manager, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite, PeopleSoft Enterprise Portal, JD Edwards EnterpriseOne Tools, OneWorld Tools, Oracle Developer Suite, and Oracle Workflow -- are prone to multiple vulnerabilities.

The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats.

Oracle has released a Critical Patch Update advisory for January 2006 to address these vulnerabilities. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier, unsupported releases are likely to be affected by the issues as well.

Exploit / POC

Oracle January Security Update Multiple Vulnerabilities

An exploit is not required for some of these issues. Other issues would likely require exploit code.

Exploit code for issue DB29 is available by Esteban Martinez Fayo <[email protected]> at:
http://www.argeniss.com/research/OraGENERATESCHEMAExploits.txt

Exploit code for issue DB05 is available by Andrea "bunker" Purificato:

Solution / Fix

Oracle January Security Update Multiple Vulnerabilities

Solution:
Oracle has released a critical patch update (Critical Patch Update - January 2006) to address these issues. Please see the referenced advisory for details on obtaining and applying the appropriate updates.

HP has released advisory HPSBMA02094 SSRT061104 rev.1 to address these issues in Oracle for OpenView. Please see the referenced advisory for further information.

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report