<?xml version="1.0"?>
<!-- RSS generated by Radio UserLand v8.0.7 on Thu, 11 Apr 2002 11:35:01 GMT -->
<rss version="0.92">
	<channel>
		<title>Pelle Braendgaard: Databases</title>
		<link>http://radio.weblogs.com/0103213/categories/databases/</link>
		<description>Oracle, SQLServer et al</description>
		<copyright>Copyright 2002 Pelle Braendgaard</copyright>
		<lastBuildDate>Thu, 11 Apr 2002 11:35:01 GMT</lastBuildDate>
		<docs>http://backend.userland.com/rss092</docs>
		<managingEditor>pelle@neubia.com</managingEditor>
		<webMaster>pelle@neubia.com</webMaster>
		<item>
			<description>&lt;H4&gt;Oracle - Unbreakable?&lt;/H4&gt;
&lt;P&gt;If you&apos;re running Oracle 9i Application Server and/or Database Server please have a look at this from CERT. There are a broad range of security holes you should now about even if you&apos;re just in Development. The largest I can see are a bunch of Buffer Overflows in the Appservers PL/SQL module.&amp;nbsp;David Litchfield of &lt;A href=&quot;http://www.nextgenss.com/&quot;&gt;NGSSoftware&lt;/A&gt; has provided a bunch of recommendations that you can reach from the CERT Advisory:&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://www.cert.org/advisories/CA-2002-08.html&quot;&gt;CA-2002-08: Multiple vulnerabilities in Oracle Servers&lt;/A&gt;&lt;/P&gt;</description>
			<source url="http://www.cert.org/channels/certcc.rdf">CERT/CC</source>
			</item>
		<item>
			<description>&lt;A href=&quot;http://www.theregister.co.uk/content/53/24513.html&quot;&gt;Sue Ellison, analyst tells Oracle users&lt;/A&gt;. Multiplexing license caper perplexes punters [&lt;A href=&quot;http://www.theregister.co.uk&quot;&gt;The Register&lt;/A&gt;]</description>
			<source url="http://www.theregister.co.uk/tonys/slashdot.rdf">The Register</source>
			</item>
		</channel>
	</rss>
