Recent Oracle vulnerabilities: any xploit in the wild?

From: M. D. (nekromancer@lycos.com)
Date: Wed Sep 08 2004 - 03:41:17 EDT


Dear colleagues,

We are trying to assess the risk for our business regarding the new Oracle vulnerabilities.

On one side we see the reported 44 detailed Oracle vulnerabilities (August 31st 2004)
from 'Application Security, Inc.'

http://www.appsecinc.com/resources/alerts/oracle/2004-0001/

and on the other side we have multiple vulnerabilities reported by NGSSoftware

http://www.nextgenss.com/advisories/oracle-01.txt,

which do not publish details about their vulnerabilities yet.

So it looks that we talk of about 70-80 actual vulnerabilities...

Are you aware of any xploits being already created for any of these?

Thank you in advance.
Kind regards,

Nekromancer

-- 
_______________________________________________
Find what you are looking for with the Lycos Yellow Pages
http://r.lycos.com/r/yp_emailfooter/http://yellowpages.lycos.com/default.asp?SRC=lycos10
------------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. All of our class sizes are
guaranteed to be 12 students or less to facilitate one-on-one interaction
with one of our expert instructors. Check out our Advanced Hacking course,
learn to write exploits and attack security infrastructure. Attend a course
taught by an expert instructor with years of in-the-field pen testing
experience in our state of the art hacking lab. Master the skills of an
Ethical Hacker to better assess the security of your organization.
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
-------------------------------------------------------------------------------


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:54:04 EDT