SMB: Malformed JPEG Download

This signature detects SMB clients downloading a malformed JPEG file. This malformed file can potentially cause vulnerable versions of Internet Explorer, or Explorer to execute arbitrary code.

Extended Description

It is reported that Oracle Database 10g and Oracle9i Database Server products contain multiple unspecified vulnerabilities. The reported vulnerabilities include SQL injection vulnerabilities and a buffer overflow issue. It is reported that the issues may be exploited by unprivileged users to gain DBA privileges or to execute arbitrary attacker-supplied code in the context of the affected database service. NGSSoftware has stated that further details will be released on 18th of April 2005 regarding the issues that are described in this BID. Please see the referenced message for more information.

Affected Products

Oracle oracle9i_lite

Short Name
SMB:EXPLOIT:MAL-JPEG-DL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SMB
Keywords
CVE-2004-0200 Download JPEG Malformed
Release Date
09/23/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Oracle

CVSS Score

9.3

Found a potential security threat?