OracleÊý¾Ý¿âJavaÐé¹¹»ú·ì϶

°ä²¼¹¦·ò 2018-08-13

·ì϶±àºÅºÍ¼¶±ð


CVE-2018-3110£¬£¬£¬£¬£¬£¬¸ßΣ£¬£¬£¬£¬£¬£¬³§ÉÌ×ÔÆÀ£º9.9£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


OracleÊý¾Ý¿â 18c£¬£¬£¬£¬£¬£¬OracleÊý¾Ý¿âWindows°æ11.2.0.4Óë12.2.0.1£¬£¬£¬£¬£¬£¬Í¬Ê±¶Ôȫƽ̨12.1.0.2ÇÒδÀûÓÃ2018Äê7ÔÂCPUµÄ°æ±¾Ò²»á²úÉúÓ°Ï죬£¬£¬£¬£¬£¬Àϰ汾ºÜ¿ÉÄܾù»áÊܵ½ÆäÓ°Ïì ¡£¡£¡£¡£¡£¡£


·ì϶¸ÅÊö

2018Äê8ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬Oracle°ä²¼°²È«¹«¸æ£¬£¬£¬£¬£¬£¬¶ÔOracleÊý¾Ý¿â·þÎñÆ÷ÖÐJavaÐé¹¹»ú´æÔڵķì϶CVE-2018-3110½øÐÐÁËÔ¤¾¯ ¡£¡£¡£¡£¡£¡£´Ë·ì϶CVSSÆÀ·ÖΪ9.9·Ö£¬£¬£¬£¬£¬£¬Ó°Ïì½ÏΪÑϳÁ£¬£¬£¬£¬£¬£¬Óû§Ó¦ÊµÊ±½øÐиüР¡£¡£¡£¡£¡£¡£´Ë·ì϶Óë2018Äê7Ô°䲼µÄCPUÖеÄCVE-2018-3004ͬԴ£¬£¬£¬£¬£¬£¬¹¥»÷·½Ê½¸üΪ¼ò»¯ ¡£¡£¡£¡£¡£¡£´Ë·ì϶»á±»¹¥»÷ÕßÀûÓÃͨ¹ýOracle Net¹¥»÷JavaÐé¹¹»ú£¬£¬£¬£¬£¬£¬¹ÌÈ»´Ë·ì϶´æÔÚÓÚJavaÐé¹¹»úÖУ¬£¬£¬£¬£¬£¬µ«¿É±»ÀûÓÃÀ´¹¥»÷ÆäËûµÄ²úÆ·Óë·þÎñ ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¹¥»÷³É¹¦ºó¿ÉÊÕÊÜÕû¸öJavaÐé¹¹»ú ¡£¡£¡£¡£¡£¡£Õâ¸ö·ì϶ÊDZØÒªÇ°ÌáǰÌáµÄ£¬£¬£¬£¬£¬£¬CVE-2018-3110 ±ØÒªÒ»¸öÊý¾Ý¿âÓû§£¬£¬£¬£¬£¬£¬¾ß±¸×î¸ù»ùµÄCREATE SESSION£¬£¬£¬£¬£¬£¬Ò²¾ÍÊÇ˵¿ÉÄÜ´´½¨»á»°£¬£¬£¬£¬£¬£¬Ïνӵ½Êý¾Ý¿â ¡£¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬£¬»ùÓÚ¶ÔÓÚ¹«¹² JAVA ¶ÔÏóµÄ½Ó¼û£¬£¬£¬£¬£¬£¬»ñµÃȨÏÞÌáÉý£¬£¬£¬£¬£¬£¬Ö±ÖÁÈ«Êý½ÚÔìÊý¾Ý¿â ¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


ÏÂΪ¹Ù·½¹«¸æÖÐÊÜÓ°Ïì²úÆ·¼°²¹¶¡¿ÉÓÃÐÔÎĵµ£º

Affected Products and Versions

Patch Availability Document

Oracle Database Server, versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18

Database



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 

·ì϶²¹¶¡½öºÏÓÃÓÚÕ¼ÓÐPremier SupportÒÔ¼°Extended Support·þÎñµÄ²úÆ·£¬£¬£¬£¬£¬£¬²»ÔÚ´ËÁеIJúÆ·²¢Î´²âÊÔÊÇ·ñ»áÊܵ½´Ë·ì϶ӰÏ죬£¬£¬£¬£¬£¬µ«ÊÇÈÔ¾ÉÍÆ¼öÓû§Éý¼¶µ½¸ü¸ß¼¶µÄ·þÎñÒÔ»ñÈ¡°²È«²¹¶¡ ¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-3110-5032149.html
https://nvd.nist.gov/vuln/detail/CVE-2018-3110