DB: Oracle TNS Listener Denial of Service

This signature detects attempts to exploit a known vulnerability against Oracle TNS Listener program, a remote connection service for Oracle Databases. Attackers can connect to the TNS Listener server and issue the SERVICE_CURLOAD command to cause the system to become unstable and unresponsive before crashing.

Extended Description

The Oracle TNS Listener program is a remote connectivity service for Oracle Databases. Under some circumstances, it may be possible for a remote user to crash TNS Listener service. By connecting to the service, and issuing the SERVICE_CURLOAD command, the service becomes unstable. It has been reported that this will cause the listenering to stop responding to connections, and also crash after the command is issued.

Affected Products

Oracle oracle8i_enterprise_edition

Short Name
DB:ORACLE:TNS:DOS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
DB
Keywords
CVE-2002-1118 Denial Listener Oracle Service TNS bid:5678 of
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Oracle

CVSS Score

5.0

Found a potential security threat?