[NEWS] Oracle TNS Listener DoS and Remote Memory Inspection



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Oracle TNS Listener DoS and Remote Memory Inspection
------------------------------------------------------------------------


SUMMARY

The TNS Listener can be crashed by an attacker causing a Denial of
Service; alternatively the attacker can use the same flaw to expose memory
contents remotely. This may reveal sensitive information.

DETAILS

There is a bug in GIOP service that can allow an attacker to crash the TNS
Listener and/or dump memory. A DWORD in the connect GIOP packet is trusted
as the size of the data in the packet.

By setting this to a large value (e.g. 0 1FFFF) causes the listener to
allocate this much memory then attempt to copy this much data to it -
which eventually leads to a read access violation because the source data
is less than this number and the process lands in uninitialized memory.
If the attacker uses a smaller number, e.g. 0xFFFF they can dump this many
bytes from memory.

This may reveal sensitive information such as the TNS Listener password.

Vendor Status:
Oracle was alerted to this flaw on the 22nd of June 2006. A patch has now
been made available:

<http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2007.html> http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2007.html


ADDITIONAL INFORMATION

The information has been provided by <mailto:davidl@xxxxxxxxxxxxxxx>
David Litchfield.
The original article can be found at:

<http://www.ngssoftware.com/advisories/high-risk-vulnerability-in-oracle-tns-listener/> http://www.ngssoftware.com/advisories/high-risk-vulnerability-in-oracle-tns-listener/



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [NT] Defeating Microsoft Windows XP SP2 Heap Protection and DEP Bypass
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... and bypassing DEP (Data Execution Prevention). ... Buffer overrun attacks are among the most common mechanisms, or vectors, ... a long string to an input stream or control longer than the memory ...
    (Securiteam)
  • [NEWS] Buffer Overflow in Mozilla Browser Firefox (Heap Corruption)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... corruption in the Mozilla browser as well as in Mozilla Firefox, ... The vulnerability specifically exists in string handling functions, ... pointing at a known memory location. ...
    (Securiteam)
  • [UNIX] Userland Can Access Linux Kernel Memory (do_brk() Argument Bound Checking)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Critical security bug has been discovered in the Linux kernel within ... The physical memory of a x86 machine running one of the recent Linux ... kernel) on all vulnerable systems. ...
    (Securiteam)
  • [TOOL] Valgrind, an Open-Source Memory Debugger for x86-GNU/Linux
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... reads and writes of memory are checked, ... As a result, Valgrind can detect ... Valgrind contains built-in support for doing very detailed cache ...
    (Securiteam)
  • [NT] Microsoft Agent Heap Overflow Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft Agent Heap Overflow Vulnerability ... The .acf format when uncompressed in memory, ... when creating the .acf file). ...
    (Securiteam)