vendor:
Oracle Database Server
by:
MC
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Oracle Database Server
Affected Version From: Oracle 9.2.0.1 Universal
Affected Version To: Oracle 9.2.0.1 Universal
Patch Exists: NO
Related CWE: CVE-2003-0727
CPE: a:oracle:oracle_database_server:9.2.0.1
Platforms Tested: Windows
2003
Oracle 9i XDB FTP PASS Overflow (win32)
By passing an overly long string to the PASS command, a stack based buffer overflow occurs. David Litchfield, has illustrated multiple vulnerabilities in the Oracle 9i XML Database (XDB), during a seminar on "Variations in exploit methods between Linux and Windows" presented at the Blackhat conference.
Mitigation:
Upgrade to a patched version of Oracle 9i.