
Cloud Vulnerability DB
A community-led vulnerabilities database
In nDPI through version 3.2, a heap-based buffer over-read vulnerability was discovered in the Oracle protocol dissector, specifically in the ndpi_search_oracle function within lib/protocols/oracle.c. The vulnerability was identified and disclosed in July 2020 (NVD, CVE).
The vulnerability occurs in the Oracle protocol dissector's packet processing functionality. The issue stems from insufficient bounds checking when processing packet payloads, leading to a heap-based buffer over-read condition. The bug was specifically identified in the ndpi_search_oracle function when processing packets on port 1521, where payload length validation was inadequate (GitHub Commit).
The exploitation of this vulnerability could result in application crashes, potentially leading to denial of service conditions for systems utilizing the nDPI library for deep packet inspection (Debian LTS).
The vulnerability can be triggered when processing Oracle protocol traffic, specifically when handling packets through the affected protocol dissector. The issue was discovered through automated fuzzing using OSS-Fuzz (OSS-Fuzz Issue).
The vulnerability has been patched in various distributions. Debian 9 (Stretch) users should upgrade to version 1.8-1+deb9u1, while Debian 10 (Buster) users should upgrade to version 2.6-3+deb10u1. The fix involves adding proper bound checking in the Oracle protocol dissector (Debian LTS, Debian LTS).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."