漏洞描述
Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTH_SESSKEY parameter length that leads to arbitrary code execution.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.oracle.comhttp://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html↗blogs.conus.infohttp://blogs.conus.info/node/28↗www.securitytracker.comhttp://www.securitytracker.com/id?1023057↗secunia.comhttp://secunia.com/advisories/37027↗osvdb.orghttp://osvdb.org/59110↗www.securityfocus.comhttp://www.securityfocus.com/archive/1/507598/100/0/threaded↗www.securityfocus.comhttp://www.securityfocus.com/bid/36747↗www.us-cert.govhttp://www.us-cert.gov/cas/techalerts/TA09-294A.html↗