J-Security Center

Title: Oracle 8 Server 'TNSLSNR80.EXE' DoS Vulnerability

Severity: MODERATE

Description:

Oracle 8 is a high-performance database used for various internet applications, e-commerce enabled sites and commonly used as a data warehouse.

A denial of service vulnerability exists in Oracle 8. An attacker connecting to port 1526 and sending invalid input will cause the 'TNSLSNR80.EXE' process to consume all available system resources, causing the server to stop responding.

'TNSLSNR80.EXE' is a server executable which allows clients to connect to the database via Oracle's SQL*Net protocol. 'TNSLSNR80.EXE' by default resides in the ORACLE_HOME\BIN directory. A Listener sits on the port waiting for connection requests from clients, the ports involved in this procedure range from 1521-1528. However only port 1526 has been reported to be affected by this vulnerability.

A restart of the server is required in order to gain normal functionality.

Affected Products:

  • Oracle Oracle8 8.0.1

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.