Oracle Database TNS Command Remote Denial of Service Vulnerability
BID:35683
Info
Oracle Database TNS Command Remote Denial of Service Vulnerability
| Bugtraq ID: | 35683 |
| Class: | Design Error |
| CVE: |
CVE-2009-1970 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2009 12:00AM |
| Updated: | Jul 24 2009 10:26PM |
| Credit: | Dennis Yurichev |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.2 .8DV Oracle Oracle9i Standard Edition 9.2 .8 Oracle Oracle9i Personal Edition 9.2 .8DV Oracle Oracle9i Enterprise Edition 9.2 .8DV Oracle Oracle11g Standard Edition 11.1 .7 Oracle Oracle11g Enterprise Edition 11.1.0.7 Oracle Oracle10g Standard Edition 10.1 .5 Oracle Oracle10g Standard Edition 10.2.0.4 Oracle Oracle10g Personal Edition 10.1 .5 Oracle Oracle10g Personal Edition 10.2.0.4 Oracle Oracle10g Enterprise Edition 10.1 .5 Oracle Oracle10g Enterprise Edition 10.2.0.4 |
| Not Vulnerable: | |
Discussion
Oracle Database TNS Command Remote Denial of Service Vulnerability
Oracle Database is prone to a remote vulnerability affecting the 'Listener' component.
The vulnerability can be exploited over the 'Oracle Net' protocol. An attacker doesn't require privileges to exploit this vulnerability.
The attacker can exploit this issue to crash the affected application, denying service to legitimate users.
The following are vulnerable:
Oracle9i 9.2.0.8 and 9.2.0.8DV
Oracle10g 10.1.0.5 and 10.2.0.4
Oracle11g 11.1.0.7
Other versions may also be affected.
Oracle Database is prone to a remote vulnerability affecting the 'Listener' component.
The vulnerability can be exploited over the 'Oracle Net' protocol. An attacker doesn't require privileges to exploit this vulnerability.
The attacker can exploit this issue to crash the affected application, denying service to legitimate users.
The following are vulnerable:
Oracle9i 9.2.0.8 and 9.2.0.8DV
Oracle10g 10.1.0.5 and 10.2.0.4
Oracle11g 11.1.0.7
Other versions may also be affected.
Exploit / POC
Oracle Database TNS Command Remote Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Oracle Database TNS Command Remote Denial of Service Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for details.
Solution:
Vendor updates are available. Please contact the vendor for details.
References
Oracle Database TNS Command Remote Denial of Service Vulnerability
References:
References:
- CVE-2009-1970 PoC (CPUjul2009) (Dennis Yurichev)
- Oracle Homepage (Oracle)
- Oracle CPUjul2009 (Dennis Yurichev
) - Oracle Critical Patch Update Advisory - July 2009 (Oracle)