vendor:
Navicat for Oracle
by:
Victor Mondragón
7.5
CVSS
HIGH
Denial of Service
CWE
Product Name: Navicat for Oracle
Affected Version From: 12.1.15
Affected Version To: 12.1.15
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Single Language x64, Windows 7 x64 Service Pack 1
2019
Navicat for Oracle 12.1.15 – “Password” Denial of Service (PoC)
This exploit causes a denial of service in Navicat for Oracle 12.1.15 by sending a specially crafted password. The exploit code is written in Python, and it opens a file called code.txt and copies its content to the clipboard. Then, it opens Navicat for Oracle and selects the 'Connection' option, followed by 'Oracle'. It fills in the necessary connection details, including a malicious IP address and a large password. When the user clicks 'Accept', the application crashes.
Mitigation:
There is no known mitigation for this vulnerability. Avoid using Navicat for Oracle 12.1.15 or update to a patched version if available.