Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

August 14th, 2012, 12:48 GMT · By

BLOG

Oracle Addresses Database Server Vulnerability Presented at Black Hat

SHARE:

Adjust text size:


Oracle fixes vulnerability in Database Server Enlarge picture - Oracle fixes vulnerability in Database Server
Oracle has recently issued a security update to address a vulnerability identified by David Litchfield and unveiled as part of his “Find me in your database: an examination of index security” presentation at Black Hat USA 2012.

The security hole doesn’t affect 11gR2 databases and it can’t be exploited by a remote attacker who doesn’t possess login credentials and specific privileges, Oracle’s Eric Maurice explained in a blog post.

However, if exploited successfully, the flaw - which involves the ‘INDEXTYPE CTXSYS.CONTEXT’ - could allow an attacker to gain “SYS” privileges, which is why customers are recommended to apply this update as soon as possible.

On the other hand, Maurice highlights the importance of responsible disclosure and advises researchers to allow them to make patches available for the issues they uncover before making their details public.

The Security Alert for CVE-2012-3132 is available here.

TELL US WHAT YOU THINK:

1,136 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


EMET 3.5 with ROP Mitigation Bypassed by Expert, Microsoft Responds

PBBans Relocates Servers After Being Hit by DDOS Attack

Chrome 21 Fixes 15 Vulnerabilities but Only Two People Get Paid

Dropbox Spam Traced to a Hijacked Employee Account

Safari Users Left Exposed with 121 Unpatched Vulnerabilities

READER COMMENTS:


Comment #1 by: Hikerj on 05 Sep 2012, 04:52 UTC reply to this comment

I installed java 7 and it has been a nightmare. It is affecting flashplayer which affects my ability to download anything on my web sites and the social media sites I need for my business. Screw you Eric Maurice. Tell the truth. The vulnerability still exists.

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM