On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jul 20, 2005 1:04:00 AM

Serious unpatched security flaws exist in certain Oracle products, according to a German security researcher who said the software maker has not fixed the bugs despite knowing about them for two years.

Alexander Kornbrust of Red Database Security published alerts on six security vulnerabilities on Tuesday. Five of the reported bugs are in the Oracle Reports enterprise reporting tool. Another is in Oracle Forms, a technology that is part of Oracle Developer Suite and is used to build applications.

"I reported these bugs two years ago," Kornbrust said in an e-mail to CNET News.com. In April, to pressure the company into providing fixes, he told the software maker that he would publish details on the bugs if they were not patched as part of the company's July security bulletin.

The most serious vulnerabilities could let an attacker gain control over an Oracle user's systems, according to the alerts. Kornbrust deems three of the bugs "high risk," two "medium risk" and one "low risk." The problems affect various versions of the Oracle products, including the newest 10g versions, he said.

Oracle declined to comment on Kornbrust's report of the flaws. A company representative did say that Oracle believes details on vulnerabilities should not be disclosed before a patch is available.

"We are disappointed when researchers act contrary to this industry best practice," the representative said in an e-mailed statement.

Kornbrust is a respected researcher, security experts from VeriSign's iDefense and eEye Digital Security said. He has discovered bugs in Oracle products in the past and those have been fixed by the software maker, they said.

Public disclosure of flaws turns up the heat on Oracle to remedy the problems but also increases the risk of attacks, said Steve Manzuik, a product manager at eEye. "It gives other people the spot to look to find the actual problems," he said.

The time that Kornbrust claims Oracle has left the vulnerabilities unpatched is "phenomenal," said Michael Sutton, a lab director at iDefense. "If true, this is one of the worst examples that I've seen of a software vendor not responsibly addressing known vulnerabilities. I'm hopeful that Oracle will publicly respond to this allegation as customers deserve an explanation," Sutton said.

eEye's Manzuik agreed. "You don't even see that with the longest Microsoft vulnerability," he said. There must have been some sort of miscommunication between Oracle and Kornbrust, he suggested.

Kornbrust believes Oracle could be playing for time. "It is easier to fix the bug silently in the next release and to wait until an old product is no longer supported," he said.

Pete Finnigan, a security specialist in York, England, said there may be as much as 250 reported but unfixed flaws in Oracle products. "Maybe they simply have not enough security people in-house to fix the bugs," he said.

Kornbrust said that he is not aware of anyone exploiting the flaws. He has offered workarounds in his advisories to protect systems. Finnigan and eEye's Manzuik recommend users apply those, after making sure the workarounds don't break their systems.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 6 Talkback(s)
Oraclesuck, fix your mix
and stop strutting around in your heels, Larry. (Read the rest)
Posted by: Boot_Agnostic Posted on: 07/23/05 You are currently: a Guest | | Terms of Use
Well, they don't need to be fixed.  Qbt | 07/19/05
Yes, shut up about that iceberg...  jorwell | 07/20/05
Did Larry say it was unbreakable, . .  Boot_Agnostic | 07/20/05
Great turnabout there, Oracle.  gordon@... | 07/19/05
Two years?!  toadlife | 07/19/05
Oraclesuck, fix your mix  Boot_Agnostic | 07/23/05

What do you think?

advertisement
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
The more you simplify, the more you save
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here