vendor:
Internet Directory
by:
Joxean Koret
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: Internet Directory
Affected Version From: 10.1.2004
Affected Version To: 10.1.2004
Patch Exists: YES
Related CWE: CVE-2008-2595
CPE: a:oracle:internet_directory:10.1.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Win2000 x86, WinXP x86, Win2003 X86_64
2008
Oracle Internet Directory 10.1.4 preauthentication Denial Of Service
Oracle Internet Directory 10.1.4 preauthentication Denial Of Service vulnerability was found by Joxean Koret. Under 32 bits platforms it crashes immediately. Under 64 bits it may take even hours. Sometimes you need 2 shoots to crash OID completely. The server 'commonly' tolerates one shoot, but even when you only send one packet it will crash. Tested on Win2000 x86, WinXP x86, Win2003 X86_64.
Mitigation:
Oracle Critical Patch Update July 2008