Oracle.Database.DBMS.TNS.Listener.DoS

Release DateJun 23, 2009
SeverityMedium
ImpactDenial of service
DescriptionThis indicates an attack attempt against a denial-of-service vulnerability in Oracle Database Server.

The vulnerability is caused by an error when the TNS Listener component handles a specially crafted TNS data packet.
Affected ProductsOracle Oracle9i 9.2.0.8
Oracle Oracle9i 9.2.0.8dv
Oracle Oracle10g 10.1.0.5
Oracle Oracle10g 10.2.0.4
Oracle Oracle11g 11.1.0.7
Recommended ActionsApply the patch released by the vendor:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0991
Reference/shttp://www.securityfocus.com/bid/34461 (BugTraq)
Reference: VID-17407