Oracle OraClient Component Insecure Installation Issue

September 6, 2005

[From Secunia]

Harry Johnston has reported a security issue in Oracle Database Server 10g, which potentially can be exploited by malicious people to compromise a user's system.

The problem is that the binary and Java Runtime directories are improperly added to the front of the system path when installing the OraClient 10g component, which contains old vulnerable versions of Info-ZIP's zip (version 2.1) and unzip (version 5.32), and Sun Java JRE (version 1.4.2_03).

The article continues at http://secunia.com/advisories/16577/