Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

FTP:OVERFLOW:PASSWORD-BO

Severity

High

Recommended

Yes

Recommended Action

Drop

Category

FTP

Keywords

8375 Metasploit FTP Password Oracle9i XDB

Release Date

2010/04/14

Update Number

1655

Supported Platforms

idp-4.0+, isg-3.4+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+

FTP: FTP Password Buffer Overflow


This signature detects attempts to exploit a known vulnerability in some FTP Servers. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

In a paper titled "Variations in exploit methods between Linux and Windows" presented at Blackhat 2003, David Litchfield has illustrated multiple vulnerabilities in the Oracle 9i XML Database (XDB). Successful exploits may allow remote attackers to run arbitrary code in the security context of the vulnerable service.

Affected Products

  • Oracle Oracle9i Enterprise Edition 9.2.0 .0.1
  • Oracle Oracle9i Personal Edition 9.2.0 .0.1
  • Oracle Oracle9i Standard Edition 9.2.0 .0.1

References

  • BugTraq: 49427
  • BugTraq: 8375
  • CVE: CVE-2006-3952
  • CVE: CVE-2009-3023
  • CVE: CVE-1999-0256
  • CVE: CVE-2003-0727

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy & Policy
Legal Notices
Copyright© 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out