It is reported to Oracle since 2004 by open3s and affects others libs. The
workaround is very simple but it is under investigation / being fixed in
main codeline. Scheduled for future cpu
regards
juan manuel pascual
On Sat, 19 Jul 2008, Joxean Koret wrote:
Oracle Database Local Untrusted
Oracle Database Local Untrusted Library Path Vulnerability
--
The Oracle July 2008 Critical Patch Update fixes a vulnerability which
allows a user in the OINSTALL/DBA group to scalate privileges to root.
Scalating Privileges from oracle to