Oracle 10g R2 and Oracle 11g suffers from a local root compromise vulnerable via the extjob binary.
5801b5819247158291af1a2ef9c8573ea460ec9ef2edb3928337fe02dab30040
iDefense Security Advisory 07.15.08 - Local exploitation of an untrusted library path vulnerability in Oracle Corp.'s Oracle Database product allows attackers to gain elevated privileges. This vulnerability specifically exists in a set-uid root program distributed with Oracle Database for Linux and Unix platforms. By replacing a module owned by the oracle user, which is loaded by this program, an attacker can execute arbitrary code as root. iDefense confirmed the existence of this vulnerability in Oracle 11g R1 version 11.1.0.6.0 on 32-bit Linux platform. Previous versions may also be affected.
01a615097a77c6303f3b770b31f3e4481133f468b5bad9ffbcfaea23ea933114