|
AppDetective™ Update 5.0.1 - 01 February 2005
ENHANCEMENTS
Oracle - NEW CHECKS
- Critical Patch Update - January 2005
Examines if the database is vulnerable to multiple critical vulnerabilities.
Risk Level - High
IBM DB2 - NEW CHECKS
- Buffer overflow in CALL statement
Examines if the database is vulnerable
to buffer overflow in CALL statement
Risk Level - High
- Buffer overflow in db2fmp
Examines if the database is vulnerable
to buffer overflow in db2fmp
Risk Level - High
- Buffer overflow in generate_distfile procedure
Examines if the database is vulnerable to
buffer overflow in generate_distfile procedure
Risk Level - High
- Buffer overflow in REC2XML function
Examines if the database is vulnerable
to buffer overflow in REC2XML function
Risk Level - High
- Multiple Buffer overflows in libdb2.so.1 library
Examines if the database is vulnerable to
multiple buffer overflows in libdb2.so.1 library
Risk Level - High
- Buffer overflow in the JDBC listener
Examines if the JDBC listener applet is
vulnerable to a stack based buffer overflow
Risk Level - High
- DoS in string formatting functions
Examines if the database is vulnerable
to to_char and to_date denial of service attacks
Risk Level - High
- Improper permissions on DB2 resources
Examines if the database is vulnerable
to various attacks because of improper permissions on certain DB2 resources
Risk Level - High
- Buffer overflows in XML Extender functions
Examines if the database is vulnerable to
buffer overflows in XML Extender functions
Risk Level - High
- Arbitrary file creation in XML Extender functions
Examines if the database is vulnerable to arbitrary
file creation vulnerabilities in XML Extender functions
Risk Level - High
- Buffer overflow in SATADMIN.SATENCRYPT function
Examines if the database is vulnerable to a
buffer overflow in the SATADMIN.SATENCRYPT function
Risk Level - Medium
Sybase - NEW CHECKS
- Multiple Vulnerabilities in Sybase ASE
Examines if the database is vulnerable to
multiple critical vulnerabilities in Sybase ASE
Risk Level - High
Microsoft SQL Server - CHECK ENHANCEMENTS
- Off-line Password Cracking Enhancements for Increased Performance
- Easily-guessed password
- Easily-guessed password for sa
- Easily-guessed password for well-known login
Return to ASAP™ Updates Listing
|