[21729] in bugtraq

home help back first fref pref prev next nref lref last post

Oracle Vulnerability Discovered in OID

daemon@ATHENA.MIT.EDU (Aaron C. Newman)
Fri Jul 20 14:00:18 2001

Reply-To: <aaron@newman-family.com>
From: "Aaron C. Newman" <aaron@newman-family.com>
To: "BUGTRAQ" <BUGTRAQ@securityfocus.com>
Date: Fri, 20 Jul 2001 11:36:46 -0400
Message-ID: <MBEGJBCJPBGIOCKFMLLPOEEKCIAA.aaron@newman-family.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
In-Reply-To: <200107200526.RAA29006@fep4-orange.clear.net.nz>

There's a new vulnerability discovered in the Oracle Internet Directory
(Oracle's LDAP server). It has been in the database since 7/16, but I
haven't seen it mentioned here yet.

Here are links to the details of the advisory:

"Oracle Internet Directory contains multiple vulnerabilities in LDAP
handling code"
http://www.kb.cert.org/vuls/id/869184

http://www.securityfocus.com/bid/3047

http://otn.oracle.com/deploy/security/pdf/oid_cert_bof.pdf


Regards,
Aaron C. Newman
CTO/Founder
Application Security, Inc.
212-490-6022
anewman@appsecinc.com
www.appsecinc.com
-Protection Where It Counts-


home help back first fref pref prev next nref lref last post