|
|
|
|
| |
Credit:
The information has been provided by Nicolas Joly.
The original article can be found at: http://seclists.org/bugtraq/2010/Oct/116
|
| |
Vulnerable Systems:
* Oracle Database 10g Release 2 version 10.2.0.3 and prior
* Oracle Database 10g Release 1 version 10.1.0.5 and prior
* Oracle Application Server 10gR2 version 10.1.2.3.0 and prior
* Oracle Identity Management 10g version 10.1.4.3 and prior
* Oracle Enterprise Manager Grid Control
The vulnerability is caused by a buffer overflow error in the EM Console when processing overly long HTTP requests, which could allow remote unauthenticated attackers to crash an affected service or execute arbitrary code via a malicious request.
Patch Availability:
Apply Oracle Critical Patch Update - October 2010:
http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
CVE Information:
CVE-2010-2390
Disclosure Timeline:
2009-11-24 - Vendor notified
2009-11-25 - Vendor response
2010-10-12 - Coordinated public Disclosure
|
|
|
|
|