CVE-2001-0517: Medium severity oracle oracle8i vulnerability
Published Jul 21, 2001
·Updated
Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transport data size that is set to 0.
Affected Software
2 affected components
Oracle Oracle8i=8.1.6
Oracle Oracle8i=8.1.7
Remediation
Patch Available
Event History
Jul 21, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0517?
CVE-2001-0517 is categorized as a denial of service vulnerability, which can severely impact database availability.
2
How do I fix CVE-2001-0517?
To fix CVE-2001-0517, ensure that you are using an updated version of Oracle 8i or apply patches provided by Oracle.
3
Which versions of Oracle are affected by CVE-2001-0517?
CVE-2001-0517 affects Oracle 8i versions 8.1.6 and 8.1.7 on Solaris.
4
What type of attack is associated with CVE-2001-0517?
CVE-2001-0517 is associated with a remote denial of service attack using malformed connection packets.
5
Is there a workaround for CVE-2001-0517?
A practical workaround for CVE-2001-0517 is to restrict access to the Oracle listener and apply network-level protections.