Oracle released the January 2008 CPU (Critical Patch Update) patch as a bugfix for some of security bugs. One of the bugs solved in the January 2008 CPU. One of the fixes is for a DoS / Poc attack written by Alexandr Polyakov which can cause the database to crash.
The exploit is published on the milw0rm website and has the following code:
set serveroutput on
/* generate evil buffer */
/* lets see the buffer size */
dbms_output.put_line('SEND EVIL BUFFER SIZE:'||Length(buff));
This is similar to the exploit Pete finnigan talked about in a post on his weblog in November 2007.