Secunia Logo
 
CVE Reference: CVE-2007-3855
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-3855

Description:
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have an unknown impact via (1) SYS.DBMS_DRS in the DataGuard component (DB03), (2) SYS.DBMS_STANDARD in the PL/SQL component (DB10), (3) MDSYS.RTREE_IDX in the Spatial component (DB16), and (4) SQL Compiler (DB17). NOTE: a reliable researcher claims that DB17 is for using Views to perform unauthorized insert, update, or delete actions.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/35490
  http://xforce.iss.net/xforce/xfdb/35495

ST
  1018415

SREASON
  http://securityreason.com/securityalert/2903

SAID
  Secunia Advisory: SA26114
  Secunia Advisory: SA26166

MISC
  http://www.red-database-security.com/advisory/oracle_view_vulnerability.html
  http://www.red-database-security.com/advisory/oracle_cpu_jul_2007.html
  http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_July_2007_Analysis.pdf
  http://rawlab.mindcreations.com/codes/exp/oracle/bunkerview.sql

HP
  http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00727143

CONFIRM
  http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2007.html

CERT
  http://www.us-cert.gov/cas/techalerts/TA07-200A.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/474326/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/473997/100/0/threaded


Return to the previous page.