OracleÊý¾Ý¿âJavaÐéÄâ»úÎó²î

Ðû²¼Ê±¼ä 2018-08-13

Îó²î±àºÅºÍ¼¶±ð


CVE-2018-3110£¬£¬£¬£¬£¬¸ßΣ£¬£¬£¬£¬£¬³§ÉÌ×ÔÆÀ£º9.9£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


OracleÊý¾Ý¿â 18c£¬£¬£¬£¬£¬OracleÊý¾Ý¿âWindows°æ11.2.0.4Óë12.2.0.1£¬£¬£¬£¬£¬Í¬Ê±¶Ôȫƽ̨12.1.0.2ÇÒδӦÓÃ2018Äê7ÔÂCPUµÄ°æ±¾Ò²»á±¬·¢Ó°Ï죬£¬£¬£¬£¬Àϰ汾ºÜ¿ÉÄܾù»áÊܵ½ÆäÓ°Ïì¡£ ¡£¡£¡£¡£


Îó²î¸ÅÊö

2018Äê8ÔÂ10ÈÕ£¬£¬£¬£¬£¬OracleÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬¶ÔOracleÊý¾Ý¿âЧÀÍÆ÷ÖÐJavaÐéÄâ»ú±£´æµÄÎó²îCVE-2018-3110¾ÙÐÐÁËÔ¤¾¯¡£ ¡£¡£¡£¡£´ËÎó²îCVSSÆÀ·ÖΪ9.9·Ö£¬£¬£¬£¬£¬Ó°Ïì½ÏΪÑÏÖØ£¬£¬£¬£¬£¬Óû§Ó¦ÊµÊ±¾ÙÐиüС£ ¡£¡£¡£¡£´ËÎó²îÓë2018Äê7ÔÂÐû²¼µÄCPUÖеÄCVE-2018-3004ͬԴ£¬£¬£¬£¬£¬¹¥»÷·½·¨¸üΪ¼ò»¯¡£ ¡£¡£¡£¡£´ËÎó²î»á±»¹¥»÷ÕßʹÓÃͨ¹ýOracle Net¹¥»÷JavaÐéÄâ»ú£¬£¬£¬£¬£¬ËäÈ»´ËÎó²î±£´æÓÚJavaÐéÄâ»úÖУ¬£¬£¬£¬£¬µ«¿É±»Ê¹ÓÃÀ´¹¥»÷ÆäËûµÄ²úÆ·ÓëЧÀÍ¡£ ¡£¡£¡£¡£¹¥»÷Õß¹¥»÷Àֳɺó¿É½ÓÊÜÕû¸öJavaÐéÄâ»ú¡£ ¡£¡£¡£¡£Õâ¸öÎó²îÊÇÐèÒªÌõ¼þÌõ¼þµÄ£¬£¬£¬£¬£¬CVE-2018-3110 ÐèÒªÒ»¸öÊý¾Ý¿âÓû§£¬£¬£¬£¬£¬¾ß±¸×î»ù±¾µÄCREATE SESSION£¬£¬£¬£¬£¬Ò²¾ÍÊÇ˵Äܹ»½¨Éè»á»°£¬£¬£¬£¬£¬ÅþÁ¬µ½Êý¾Ý¿â¡£ ¡£¡£¡£¡£È»ºó£¬£¬£¬£¬£¬»ùÓÚ¹ØÓÚ¹«¹² JAVA ¹¤¾ßµÄ»á¼û£¬£¬£¬£¬£¬»ñµÃȨÏÞÌáÉý£¬£¬£¬£¬£¬Ö±ÖÁËùÓпØÖÆÊý¾Ý¿â¡£ ¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÂΪ¹Ù·½Í¨¸æÖÐÊÜÓ°Ïì²úÆ·¼°²¹¶¡¿ÉÓÃÐÔÎĵµ£º

Affected Products and Versions

Patch Availability Document

Oracle Database Server, versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18

Database



¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 

Îó²î²¹¶¡½öÊÊÓÃÓÚÓµÓÐPremier SupportÒÔ¼°Extended SupportЧÀ͵IJúÆ·£¬£¬£¬£¬£¬²»ÔÚ´ËÁеIJúÆ·²¢Î´²âÊÔÊÇ·ñ»áÊܵ½´ËÎó²îÓ°Ï죬£¬£¬£¬£¬¿ÉÊÇÈÔÈ»ÍÆ¼öÓû§Éý¼¶µ½¸ü¸ß¼¶µÄЧÀÍÒÔ»ñÈ¡Çå¾²²¹¶¡¡£ ¡£¡£¡£¡£


²Î¿¼Á´½Ó


http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-3110-5032149.html
https://nvd.nist.gov/vuln/detail/CVE-2018-3110