Oracle.Secure.Backup.Observiced.Code

NameOracle.Secure.Backup.Observiced.Code.Execution
Release DateFeb 01, 2010
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a stack-overflow vulnerability in
Oracle Secure backup.

The vulnerability is caused by an error when the vulnerable software handles
malicious DNS responses. It allows a remote attacker to execute arbitrary code via sending crafted DNS packets.
Affected ProductsOracle Secure Backup version 10.2.0.3
Recommended ActionsApply the patch released by the vendor for this issue:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0072
Reference/shttp://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html
http://www.zerodayinitiative.com/advisories/ZDI-10-002/
Reference: VID-18116