Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Oracle 9iAS Apache PL/SQL Module Denial of Service Vulnerability

The Oracle 9iAS web service is powered by the Apache webserver. Included is an Apache module for PL/SQL support.

If a request is made to the pls module with a HTTP client authorization header set, and with no auth type defined, the server will suffer an access violation error. A restart is required in order to regain normal functionality.

It has been reported that this is not the result of a buffer overflow, and it is not believed to be exploitable to execute code.







 

Privacy Statement
Copyright 2008, SecurityFocus