Korean
<< Back
VID 12029
Severity 30
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The Oracle Webserver is vulnerable to a Denial of Service attack via a long URL request.
The Oracle WebServer combines the power of Oracle7 with World Wide Web versatility. The version 2.1 of Oracle WebServer is affected by a Denial of Service attacker via a long URL request. When serving PL/SQL Stored Procedures in /ows-bin/, if a remote attacker sends a URL request with a too long argument to the cgi /ows-bin/fnord as the following:

GET /ows-bin/fnord?foo=AAAAA....['A'*2048]....AAAAA

It was possible to make the remote web server crash. A remote attacker may use this vulnerability to prevent legitimate users to access web site.

* References:
http://archives.neohapsis.com/archives/bugtraq/1997_3/0135.html
http://www.iss.net/security_center/static/1812.php

* Platforms Affected:
Oracle WebServer 2.1
Recommendation No solution available as of June 2014.

As a workaround, administrators should restrict access to the Oracle Web server to trusted hosts.
Or remove the CGI "fnord".
Related URL CVE-1999-1068 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)