Oracle Affected

Notified:  April 06, 2001 Updated: December 12, 2002

Status

Affected

Vendor Statement

Oracle has prepared a Solaris-based patch set for Oracle Internet Directory versions 2.1.1.x and 3.0.1. These patches were made available on July 17, 2001 to Oracle Internet Directory customers via the Oracle MetaLink (http://metalink.oracle.com/) system. Please visit Oracle Technology Network at http://otn.oracle.com/deploy/security/alerts.htm for details on workarounds and patch availability information for the potential buffer overflow vulnerabilities discovered in Oracle Internet Directory.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

For further information regarding the Oracle response to this vulnerability, please see http://otn.oracle.com/deploy/security/pdf/oid_cert_bof.pdf