Re: Analysis of the Oracle October 2006 Critical Patch Update
vile <[email protected]> Wed, 18 Oct 2006 13:35:13 -0500
| Newsgroups | gmane.comp.security.full-disclosure,gmane.comp.security.ntbugtraq,gmane.comp.security.bugtraq |
|---|---|
| Message-ID | <[email protected]> |
--===============0221981394== Content-Type: multipart/alternative; boundary="----=_Part_1801_17418768.1161196513692" ------=_Part_1801_17418768.1161196513692 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline i butt fucked your sister, David. She moaned like a little bitch. On 10/18/06, Paul Schmehl <[email protected]> wrote: > > Thanks, David, for your always enlightening (and depressing if you use > Oracle products) reports on the unbreakable database. > > --On Wednesday, October 18, 2006 07:55:35 +0100 David Litchfield > <[email protected]> wrote: > > > Hey all, > > I've just posted an analysis of the 22 Oracle RDBMS flaws patched by the > > October 2006 Critical Patch Update that was released yesterday: > > > http://www.oracle.com/technology/deploy/security/critical-patch-updates/c > > puoct2006.html. Further, it's a shame to see that, after a promising > > July 2006 CPU where Oracle had all the patches ready *on time*, they > > have slipped back into their old, bad habits - patches are not ready > for > > a number of platforms. I thought they'd solved those issues - but > > clearly not. You can get a copy of the analysis from > > http://www.databasesecurity.com/oracle/OracleOct2006-CPU-Analysis.pdf, > > Cheers, > > David Litchfield > > NGSSoftware Ltd > > http://www.ngssoftware.com/ > > +44(0) 208 401 0070 > > > > > > > > > > _______________________________________________ > > Full-Disclosure - We believe in it. > > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > > Hosted and sponsored by Secunia - http://secunia.com/ > > > > Paul Schmehl ([email protected]) > Adjunct Information Security Officer > The University of Texas at Dallas > http://www.utdallas.edu/ir/security/ > > > _______________________________________________ > Full-Disclosure - We believe in it. > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > Hosted and sponsored by Secunia - http://secunia.com/ > > > ------=_Part_1801_17418768.1161196513692 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline i butt fucked your sister, David. She moaned like a little bitch.<br><br> <div><span class="gmail_quote">On 10/18/06, <b class="gmail_sendername">Paul Schmehl</b> <<a href="mailto:[email protected]">[email protected]</a>> wrote:</span> <blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">Thanks, David, for your always enlightening (and depressing if you use<br>Oracle products) reports on the unbreakable database. <br><br>--On Wednesday, October 18, 2006 07:55:35 +0100 David Litchfield<br><<a href="mailto:[email protected]">[email protected]</a>> wrote:<br><br>> Hey all,<br>> I've just posted an analysis of the 22 Oracle RDBMS flaws patched by the <br>> October 2006 Critical Patch Update that was released yesterday:<br>> <a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/c">http://www.oracle.com/technology/deploy/security/critical-patch-updates/c </a><br>> puoct2006.html. Further, it's a shame to see that, after a promising<br>> July 2006 CPU where Oracle had all the patches ready *on time*, they<br>> have slipped back into their old, bad habits - patches are not ready for <br>> a number of platforms. I thought they'd solved those issues - but<br>> clearly not. You can get a copy of the analysis from<br>> <a href="http://www.databasesecurity.com/oracle/OracleOct2006-CPU-Analysis.pdf"> http://www.databasesecurity.com/oracle/OracleOct2006-CPU-Analysis.pdf</a>,<br>> Cheers,<br>> David Litchfield<br>> NGSSoftware Ltd<br>> <a href="http://www.ngssoftware.com/">http://www.ngssoftware.com/</a><br> > +44(0) 208 401 0070<br>><br>><br>><br>><br>> _______________________________________________<br>> Full-Disclosure - We believe in it.<br>> Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html"> http://lists.grok.org.uk/full-disclosure-charter.html</a><br>> Hosted and sponsored by Secunia - <a href="http://secunia.com/">http://secunia.com/</a><br><br><br><br>Paul Schmehl (<a href="mailto:[email protected]">[email protected] </a>)<br>Adjunct Information Security Officer<br>The University of Texas at Dallas<br><a href="http://www.utdallas.edu/ir/security/">http://www.utdallas.edu/ir/security/</a><br><br><br>_______________________________________________ <br>Full-Disclosure - We believe in it.<br>Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html">http://lists.grok.org.uk/full-disclosure-charter.html</a><br>Hosted and sponsored by Secunia - <a href="http://secunia.com/"> http://secunia.com/</a><br><br><br></blockquote></div><br> ------=_Part_1801_17418768.1161196513692-- --===============0221981394== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ --===============0221981394==--