Oracle Information for VU#869184
Oracle Internet Directory contains multiple vulnerabilities in LDAP handling code
- Vendor Information Help Date Notified: 06 Apr 2001
- Statement Date:
- Date Updated: 12 Dec 2002
Status
Affected
Vendor Statement
Oracle has prepared a Solaris-based patch set for Oracle Internet Directory versions 2.1.1.x and 3.0.1. These patches were made available on July 17, 2001 to Oracle Internet Directory customers via the Oracle MetaLink (http://metalink.oracle.com/) system.
Please visit Oracle Technology Network at http://otn.oracle.com/deploy/security/alerts.htm for details on workarounds and patch availability information for the potential buffer overflow vulnerabilities discovered in Oracle Internet Directory.
Vendor Information
The vendor has not provided us with any further information regarding this vulnerability.
Vendor References
None
Addendum
For further information regarding the Oracle response to this vulnerability, please see
- http://otn.oracle.com/deploy/security/pdf/oid_cert_bof.pdf
If you have feedback, comments, or additional information about this vulnerability, please send us email.