Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Internet_directory | Oracle | 2.1.1 (including) | 2.1.1 (including) |
Internet_directory | Oracle | 3.0.1 (including) | 3.0.1 (including) |