vendor:
Oracle 8.0
by:
r0ot@runbox.com
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Oracle 8.0
Affected Version From: Oracle 8.0
Affected Version To: Oracle 8.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows NT 4.0 (Sp6)
2001
Denial of Service Vulnerability in Oracle 8
An attacker connecting to port 1526 and sending invalid input will cause the 'TNSLSNR80.EXE' process to consume all available system resources, causing the server to stop responding. A Perl script is provided which can be used to crash Oracle 8.0 on Windows NT 4.0 (Sp6).
Mitigation:
Ensure that the Oracle server is not exposed to the public internet and that access is restricted to trusted users.