[10454] in bugtraq
Re: *Huge* security hole in Oracle 8.0.5 with Intellegent agent
daemon@ATHENA.MIT.EDU (Yung-Sheng Tang)
Thu May 6 16:13:06 1999
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Message-Id: <Pine.GSO.4.05.9905051649030.15339-100000@db85>
Date: Wed, 5 May 1999 16:52:44 +0800
Reply-To: Yung-Sheng Tang <jeff@DB.CSIE.NCU.EDU.TW>
From: Yung-Sheng Tang <jeff@DB.CSIE.NCU.EDU.TW>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <199905041341.JAA26557@paranor.wpafb.af.mil>
On Tue, 4 May 1999, Paul Diehl wrote:
> On Fri, Apr 30, 1999 at 02:11:39PM +0100, Anthony Clarke wrote:
> > This hole has been verified on both Linux and Solaris with Oracle 8.0.5. It
> > probably exists in all Unix versions of 8.0.5. Whether it exists in later
> > versions is unknown. (I don't believe it exists in 8.0.4, but I can't
> > verify that at the moment)
>
> This hole exists for Oracle 8.0.3 on Solaris as well.
>
Maybe not. Our Oracle 8.0.3 on Solaris doesn't have root-owned oratclsh.