Oracle Database Network Foundation CVE-2011-0806 Remote Denial of Service Vulnerability
BID:47430
Info
Oracle Database Network Foundation CVE-2011-0806 Remote Denial of Service Vulnerability
| Bugtraq ID: | 47430 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-0806 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 19 2011 12:00AM |
| Updated: | May 02 2011 04:33PM |
| Credit: | Esteban Martinez Fayo of Application Security Inc. |
| Vulnerable: |
Oracle Oracle11g Standard Edition 11.1 .7 Oracle Oracle11g Standard Edition 11.2.0.2.0 Oracle Oracle11g Standard Edition 11.2.0.1.0 Oracle Oracle11g Standard Edition 11.1.0.7 R1 Oracle Oracle10g Standard Edition 10.3 .1 Oracle Oracle10g Standard Edition 10.2 .5 Oracle Oracle10g Standard Edition 10.2 .3 Oracle Oracle10g Standard Edition 10.1 .5 Oracle Oracle10g Personal Edition 10.2 .5 Oracle Oracle10g Personal Edition 10.2 .1 Oracle Oracle10g Personal Edition 10.2.0.4 Oracle Oracle10g Enterprise Edition 10.2 .5 Oracle Oracle10g Enterprise Edition 10.1 .5 Oracle Oracle10g Enterprise Edition 10.2.0.4 |
| Not Vulnerable: | |
Discussion
Oracle Database Network Foundation CVE-2011-0806 Remote Denial of Service Vulnerability
Oracle Database is prone to a remote denial-of-service vulnerability in Network Foundation.
The vulnerability can be exploited over the 'Oracle Net' protocol. An attacker does not require privileges to exploit this vulnerability.
Attackers can exploit this issue to consume all available CPU resources, denying service to legitimate users.
Note: To exploit this issue, attackers need to know the SID or Service Name of the database.
This vulnerability affects the following supported versions:
10.1.0.5, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, 11.2.0.2
Oracle Database is prone to a remote denial-of-service vulnerability in Network Foundation.
The vulnerability can be exploited over the 'Oracle Net' protocol. An attacker does not require privileges to exploit this vulnerability.
Attackers can exploit this issue to consume all available CPU resources, denying service to legitimate users.
Note: To exploit this issue, attackers need to know the SID or Service Name of the database.
This vulnerability affects the following supported versions:
10.1.0.5, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, 11.2.0.2
Exploit / POC
Oracle Database Network Foundation CVE-2011-0806 Remote Denial of Service Vulnerability
Attacker can exploit this issue by sending a specially crafted packet to a vulnerable server.
Attacker can exploit this issue by sending a specially crafted packet to a vulnerable server.
Solution / Fix
Oracle Database Network Foundation CVE-2011-0806 Remote Denial of Service Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle Database Network Foundation CVE-2011-0806 Remote Denial of Service Vulnerability
References:
References: