A potential security vulnerability has been discovered in Oracle Internet Directory (OID). OID release 2.1.1.0.0 is vulnerable to a potential buffer overflow problem which may permit unauthorized access to the operating system. Products Oracle Internet Directory (OID) release 2.1.1.0.0 On Unix platforms 1. Change the ownership of executable “ oidldapd”from root user to the UNIX user who owns the OID installation in the operating system. 2. Set the file permissions on “ oidldapd”to 710. 3. Change the ownership of executable “ oidmon”from root user to the UNIX user who owns the OID installation in the operating system.

4. Set the file permissions on “ oidmon”to 710. 5. Remove (or back up) OID monitor and dispatcher log files before restarting the OID instance. On Windows 2000 On Windows NT 1) OID release 3.0.1.1.0 (shipping with Oracle9i) on all Unix platforms 2) OID release 3.0.1.1.0 (shipping with Oracle9i) on Windows 3) OID release 2.1.1.3.0 (shipping with Oracle8i) on Solaris.

Download Oracle Internet Directory Buffer Overflow Vulnerability