DB: Oracle Insecure TNS Listener Configuration
This signature detects an Oracle Database instance where the listener security options have been disabled, enabling database access for any connection (including attackers). Servers triggering this signature should be reviewed by a qualified Oracle DBA for security concerns.
Extended Description
A denial of service vulnerability exists in Oracle 8i. An attacker connecting to the host and sending a malformed SQLNet (Type-1) connection request, could cause the host to stop responding.
Affected Products
Oracle oracle8
References
BugTraq: 2940
CVE: CVE-2001-0498
URL: http://www.securityfocus.com/archive/1/68924 http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Oracle
5.0