Oracle Information for VU#869184

Oracle Internet Directory contains multiple vulnerabilities in LDAP handling code



Vendor Statement

Oracle has prepared a Solaris-based patch set for Oracle Internet Directory versions 2.1.1.x and 3.0.1. These patches were made available on July 17, 2001 to Oracle Internet Directory customers via the Oracle MetaLink ( system.

Please visit Oracle Technology Network at for details on workarounds and patch availability information for the potential buffer overflow vulnerabilities discovered in Oracle Internet Directory.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References



For further information regarding the Oracle response to this vulnerability, please see