DB: Oracle TNS Listener Denial of Service
This signature detects attempts to exploit a known vulnerability against Oracle TNS Listener program, a remote connection service for Oracle Databases. Attackers can connect to the TNS Listener server and issue the SERVICE_CURLOAD command to cause the system to become unstable and unresponsive before crashing.
Extended Description
The Oracle TNS Listener program is a remote connectivity service for Oracle Databases. Under some circumstances, it may be possible for a remote user to crash TNS Listener service. By connecting to the service, and issuing the SERVICE_CURLOAD command, the service becomes unstable. It has been reported that this will cause the listenering to stop responding to connections, and also crash after the command is issued.
Affected Products
Oracle oracle8i_enterprise_edition
References
BugTraq: 5678
CVE: CVE-2002-1118
URL: http://online.securityfocus.com/advisories/4545 http://otn.oracle.com/deploy/security/pdf/2002alert42.pdf
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Oracle
5.0