hacking security forum

[Full-Disclosure] Oracle exploit? Where's the beef?

From: Mark Shirley <mshirley@gmail.com>
Date: Wed Sep 01 2004 - 11:34:32 EDT

Does anyone know anything further about the new oracle exploit? It
seems no one is saying shit about it other then "it's bad, it affects
everything, patch patch patc".

This is the only url i could find that has anything remotely interesting.

http://www.ciac.org/ciac/bulletins/o-209.shtml

VULNERABILITY ASSESSMENT: Oracle rates this as a HIGH. "Exploiting
some of the vulnerabilities requires network access, but no valid user
account."

Typical response from oracle, "DAMAGE: Oracle does not give
descriptions of the vulnerabilities on this alert."

Remote exploits are bad mmkay.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Wed Sep 01 13:54:45 2004

This archive was generated by hypermail 2.1.8 : Wed Sep 01 2004 - 14:01:15 EDT

Custom Search