|
Oracle Multiple Product OpenSSL Vulnerabilities
|
|
Secunia Advisory:
|
SA10371
|
|
|
Release Date:
|
2003-12-05
|
|
Popularity:
|
9,889 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
Exposure of sensitive information DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Oracle Database 8.x Oracle HTTP Server 8.x Oracle HTTP Server 9.x Oracle9i Application Server Oracle9i Database Enterprise Edition Oracle9i Database Standard Edition
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2002-0082 CVE-2003-0078 CVE-2003-0131 CVE-2003-0147 CVE-2003-0543 CVE-2003-0544 CVE-2003-0545
|
|
Description: Oracle has confirmed that various products are affected by some OpenSSL vulnerabilities, which can be exploited by malicious people to gain knowledge of sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.
For more information:
SA8101
SA8330
SA8360
SA9886
Oracle reports the following products as affected:
* Oracle9i Database Server Release 2, Version 9.2.0.
* Oracle9i Database Server Release 1, Version 9.0.1.
* Oracle8i Database Server Release 3, Version 8.1.7.
* Oracle9i Application Server Version 9.0.2.
* Oracle9i Application Server Version 9.0.3.
* Oracle9i Application Server Release 1, Version 1.0.2.2.
* Oracle9i Application Server Release 1, Version 1.0.2.1s.
* Oracle HTTP Server Version 9.2.
* Oracle HTTP Server Version 9.0.1.
* Oracle HTTP Server Version 8.1.7.
Solution: Apply patches - see patch matrix at:
http://metalink.oracle.com/metalink/p...?p_database_id=NOTE&p_id=249034.1
Original Advisory: http://otn.oracle.com/deploy/security/pdf/2003alert62.pdf
Other References: SA8101:
http://secunia.com/advisories/8101/
SA8330:
http://secunia.com/advisories/8330/
SA8360:
http://secunia.com/advisories/8360/
SA9886:
http://secunia.com/advisories/9886/
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|