Apache Web Server Flaw: Sun patched it, did Oracle?

From: marcus peddle (marcus_peddle_at_yahoo.ca)
Date: 10/19/04

  • Next message: GuidoZ: "Re: Client End Firewalls"
    Date: Mon, 18 Oct 2004 20:02:28 -0400 (EDT)
    To: security-basics@securityfocus.com
    
    

    Greetings all,

    I work in a telecommunications product that utilizes
    the Oracle version of the Apache web server. Sun has
    recently released a patch for for it's version of the
    Apache web server as highlighted by the following:

    http://secunia.com/advisories/12377/

    My question is if the same security flaws have been
    identified with the Oracle version as was with the
    Solaris version? If Solaris is releasing this patch,
    how do I determine if Oracle will be releasing the
    same (if they have not already).

    I bring my questions to the forum as I am not too
    familiar with the Apache web server and the
    introduction of product security into my job role is a
    recent development so I'm hoping someone here has
    experienced the same dilemma.

    Your responses are appreciated,
    Marcus

    ______________________________________________________________________
    Post your free ad now! http://personals.yahoo.ca


  • Next message: GuidoZ: "Re: Client End Firewalls"

    Relevant Pages

    • RE: MDAC 2.8 win 2003 x64 Ole Db Problem
      ... Word from Microsoft is that they will NOT be releasing an x^$ version of ... "Andy" wrote: ... > I checked the Oracle web site as well, ... >> that the msdaora.dll for x64 is not available yet. ...
      (microsoft.public.data.oledb)
    • [Full-disclosure] Inguma version 0.0.7.2 released
      ... new modules and exploits, fixed many, many, many bugs as well as ... enhancing existing modules, such as the Oracle related stuff. ... I'm releasing 5 new Oracle ...
      (Full-Disclosure)
    • Inguma version 0.0.7.2 released
      ... new modules and exploits, fixed many, many, many bugs as well as ... enhancing existing modules, such as the Oracle related stuff. ... I'm releasing 5 new Oracle ...
      (Pen-Test)
    • Using Oracle APEX (ApplicationExpress) on VMS / installing mod_plsql on apache
      ... I have the Apache web server and Oracle databases already running on my VMS ... Is anyone using APEX in this environment? ...
      (comp.databases.oracle.server)
    • Re: Oracle Posts Exploit Code for Database Flaw
      ... Oracle released a note on the Oracle ... Delete Rows from a View" was available last week to Metalink customers. ... vulnerability in order to avoid/mitigate the risk whilst ... I informed Oracle secalert that releasing such ...
      (comp.databases.oracle.server)

  • Quantcast