Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2012:0765-1 Important: Oracle Server Local Listener Issue

suse
Calendar Grey June 20, 2012
Scroller Suse
Essential SUSE upgrade addressing Oracle flaw and five further bugs, comprehensive patch guidance provided.
An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is now...

Summary

This package wraps the Oracle Server update process for the Oracle server included in SUSE Manager. On installation of this package it will pull and install the Oracle updates and patches, integrated so that SUSE Manager is correctly stopped, the databases converted and restarted. It contains a security helper script that may adjust the Oracle server listening on all network interfaces to just listen on localhost (CVE-2012-1675). To switch to a configuration that will restrict the listener to localhost only run the following command as root: spacewalk-service stop /opt/apps/db-update/smdba-netswitch localhost spacewalk-service start In case you want to revert to the previous configuration, just run: spacewalk-service stop /opt/apps/db-update/smdba-netswitch worldwide spacewalk-service start

References

#736238 #757705 #760074 #760660 #763895 #764049

Cross- CVE-2012-1675

Affected Products:

SUSE Manager 1.2 for SLE 11 SP1

https://www.suse.com/security/cve/CVE-2012-1675.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:0765-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.