vendor:
                    Oracle Database Server
                by:
                    MC
                7.5
                        CVSS
                    HIGH
                    Buffer Overflow
                    119
                        CWE
                    Product Name: Oracle Database Server
                    Affected Version From:  Oracle 9.2.0.1 Universal
                    Affected Version To:  Oracle 9.2.0.1 Universal
                    Patch Exists: NO
                    Related CWE: CVE-2003-0727
                    CPE:  a:oracle:oracle_database_server:9.2.0.1
                    Platforms Tested:  Windows
                    2003
                    Oracle 9i XDB FTP PASS Overflow (win32)
By passing an overly long string to the PASS command, a stack based buffer overflow occurs. David Litchfield, has illustrated multiple vulnerabilities in the Oracle 9i XML Database (XDB), during a seminar on "Variations in exploit methods between Linux and Windows" presented at the Blackhat conference.
Mitigation:
					Upgrade to a patched version of Oracle 9i.