Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

DB:ORACLE:TNS:DOS

Severity

High

Recommended

No

Recommended Action

Drop

Category

DB

Keywords

Oracle TNS Listener Denial of Service

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

DB: Oracle TNS Listener Denial of Service


This signature detects attempts to exploit a known vulnerability against Oracle TNS Listener program, a remote connection service for Oracle Databases. Attackers can connect to the TNS Listener server and issue the SERVICE_CURLOAD command to cause the system to become unstable and unresponsive before crashing.

Extended Description

The Oracle TNS Listener program is a remote connectivity service for Oracle Databases. Under some circumstances, it may be possible for a remote user to crash TNS Listener service. By connecting to the service, and issuing the SERVICE_CURLOAD command, the service becomes unstable. It has been reported that this will cause the listenering to stop responding to connections, and also crash after the command is issued.

Affected Products

  • Oracle Oracle8i Enterprise Edition 8.1.5 .0.0
  • Oracle Oracle8i Enterprise Edition 8.1.5 .0.2
  • Oracle Oracle8i Enterprise Edition 8.1.5 .1.0
  • Oracle Oracle8i Enterprise Edition 8.1.6 .0.0
  • Oracle Oracle8i Enterprise Edition 8.1.6 .1.0
  • Oracle Oracle8i Enterprise Edition 8.1.7 .0.0
  • Oracle Oracle8i Enterprise Edition 8.1.7 .1.0
  • Oracle Oracle8i Standard Edition 8.1.5
  • Oracle Oracle8i Standard Edition 8.1.6
  • Oracle Oracle8i Standard Edition 8.1.7
  • Oracle Oracle8i Standard Edition 8.1.7 .1
  • Oracle Oracle8i Standard Edition 8.1.7 .4
  • Oracle Oracle9i Standard Edition 9.0.0
  • Oracle Oracle9i Standard Edition 9.0.1
  • Oracle Oracle9i Standard Edition 9.0.1 .2
  • Oracle Oracle9i Standard Edition 9.0.1 .3
  • Oracle Oracle9i Standard Edition 9.0.1 .4
  • Oracle Oracle9i Standard Edition 9.0.2
  • Oracle Oracle9i Standard Edition 9.2.0 .0.1
  • Oracle Oracle9i Standard Edition 9.2.0 .0.2
  • Oracle Oracle9i Standard Edition 9.2.0 .1
  • Oracle Oracle9i Standard Edition 9.2.0 .2

References

  • BugTraq: 5678
  • CVE: CVE-2002-1118
  • URL: http://online.securityfocus.com/advisories/4545
  • URL: http://otn.oracle.com/deploy/security/pdf/2002alert42.pdf

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out