Sponsored Links

 

 

 

Oracle SQL*Net and Net8 Malformed Packet Denial of Service ...

Source: www.oracle.com
Topic: Oracle Programming


Short Desciption:
Oracle SQL*Net and Net8 Malformed Packet Denial of Service Vulnerability Overview A potential security vulnerability has been discovered in Net8 (formerly known as SQL*Net). The Oracle8i database ...

 

Content Inside:
Oracle SQL*Net and Net8 Malformed Packet Denial of Service Vulnerability Overview A potential security vulnerability has been discovered in Net8 (formerly known as SQL*Net). The Oracle8i database server relies on multiple services for its distributed client server computing functionality. Services that are dependant upon the TNS include the TNS Listener, Oracle Name Service and the Oracle Connections Manager. These servers accept  client requests and establish TNS data connections between the clients and the services. A vulnerability exists in the TNS libraries which process Net8 packets. This vulnerability will enable an attacker to mount a denial of service attack against any of the above services by issuing a malformed Net8 connection request. Products All releases of the Oracle Listener (database releases Oracle 7.3.x, Oracle 8.0.x, Oracle 8.1.x) Platforms All platforms Patch Solution Oracle has fixed this potential security vulnerability in the Oracle9i database server. Oracle is in the process of backporting the fix to supported Oracle8i database server Releases 8.1.7 (patchsets 81.7.2 and 8.1.7.3) and 8.1.6 and Oracle8 Release 8.0.6  on all platforms. Download the patch for your platform from Oracles Worldwide Support web site, Metalink, http://metalink. oracle.com. Please check Metalink periodically for patch availability if the patch for your platform is not yet available. Please see the matrix posted below this Alert for details on patch availability and schedules. Credits Oracle would like to thank COVERT Labs at PGP Security (Network Associates) for discovering this potential security vulnerability and promptly bringing it to Oracles attention.

 

add to Google Reader add to Google Bookmark add to bloglines add to newsgator add to FURL add to digg add to webnews add to Netscape add to Yahoo MyWeb add to spurl.net add to diigo Bookmark newsvine Bookmark del.icio.us Bookmark @ SIMPIFY Bookmark MISTER WONG Bookmark Linkarena Bookmark icio.de Bookmark oneview Bookmark folkd.com Bookmark yigg.de Bookmark reddit Bookmark StumbleUpon Bookmark Slashdot Bookmark blinklist Bookmark technorati add to blogmarks add to blinkbits add to ma.gnolia add to smarking.com add to netvouz add to co.mments add to Connotea add to de.lirio.us

 

Related PDF Files

Oracle® Application Server 10 g Quick Installation and Upgrade Guide


Topic: Oracle Programming

16 Oracle Application Server To create the oracle operating system user for the Portal and Wireless Developer topology, enter the following command as the root user: # /usr/sbin/useradd -g oinstall -G dba ...

Oracle Database Recovery Manager Quick Start Guide


Topic: Oracle Programming

Oracle® Database Recovery Manager Quick Start Guide Oracle Database Recovery Manager Quick Start Guide

Oracle SQL Tuning Pocket Reference*


Topic: Oracle Programming

www . DanHotka .com Quarterly Newsletter DHotka@Earthlink.net Winter 2003 Dan Hotka is a Training Specialist who has over 24 years in the computer industry and over 19 years experience with Oracle ...

Intro to PL/SQL


Topic: Oracle Programming

Introduction to PL/SQL 2-day Workshop Give your IT staff the knowledge of using Oracles procedural language: PL/SQL. The focus of this course is to students with a working knowledge of SQL the ...

Oracle Migration Workbench Reference Guide for MySQL 3.22, 3.23 ...


Topic: Oracle Programming

Oracle Migration Workbench Reference Guide for MySQL 3.22, 3.23 Migrations, Release 9.2.0 for Microsoft ... You can use PL/SQL to write stored programs and triggers in Oracle. It is also the programming ...

 

Sponsored Links