5
CVSSv2

CVE-2008-2595

Published: 15/07/2008 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a denial of service (crash) via a malformed LDAP request that triggers a NULL pointer dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle database 10g 10.1.2.3

oracle database 10g 10.1.4.2

oracle database 9i 9.0.4.3

Exploits

#!/usr/bin/python """ Oracle Internet Directory 1014 preauthentication Denial Of Service NOTES: Under 32 bits platforms it crashes immediately Under 64 bits it may take even hours Sometimes you need 2 shoots to crash OID completely The server "commonly" tolerates one shoot, but even when you only send one packet it will crash Tested: Win20 ...
Oracle Internet Directory version 1014 remote pre-authentication denial of service exploit ...