Short Name |
FTP:OVERFLOW:ORACLE-UNLOCK |
|---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
FTP |
Keywords |
Oracle 9i UNLOCK XDB Overflow |
Release Date |
2010/08/13 |
Update Number |
1752 |
Supported Platforms |
idp-4.0+, isg-3.4+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+ |
This signature detects attempts to exploit a known vulnerability in the Oracle 9i XDB. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.
In a paper titled "Variations in exploit methods between Linux and Windows" presented at Blackhat 2003, David Litchfield has illustrated multiple vulnerabilities in the Oracle 9i XML Database (XDB). Successful exploits may allow remote attackers to run arbitrary code in the security context of the vulnerable service.