Re: [Full-disclosure] Oracle Database Local Untrusted Library Path Vulnerability

2008-07-21 Thread jmpascual
It is reported to Oracle since 2004 by open3s and affects others libs. The workaround is very simple but it is under investigation / being fixed in main codeline. Scheduled for future cpu regards juan manuel pascual On Sat, 19 Jul 2008, Joxean Koret wrote: Oracle Database Local Untrusted

[Full-disclosure] Oracle Database Local Untrusted Library Path Vulnerability

2008-07-19 Thread Joxean Koret
Oracle Database Local Untrusted Library Path Vulnerability -- The Oracle July 2008 Critical Patch Update fixes a vulnerability which allows a user in the OINSTALL/DBA group to scalate privileges to root. Scalating Privileges from oracle to