Oracle.NDMP.CONNECT.CLIENT.AUTH.User.ID

NameOracle.NDMP.CONNECT.CLIENT.AUTH.User.ID.Buffer.Overflow
Last Updated DateFeb 03, 2009
Release DateJan 13, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates a possible attempt to exploit a buffer-overflow vulnerability in Oracle Secure Backup.

The vulnerability is located in obndmpd.exe while handling malformed NDMP_CONNECT_CLIENT_AUTH commands. It may allow remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts will likely cause the program to crash, resulting in a denial-of-service condition.
Affected ProductsOracle Secure Backup 10.2
Recommended ActionsRefer to the vendor's web site for the suggested workaround:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2009.html
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-5444
Reference: VID-15751