Oracle pushes emergency DDoS vulnerability patch

Oracle pushes emergency DDoS vulnerability patch

تاریخ ایجاد

ID: IRCNE2011091256
Date: 2011-09-20

According to "itpro", Oracle has issued an out-of-cycle patch for a denial of service flaw in the Apache web server, versions httpd 2.0 or 2.2.
Whilst Oracle has not given the vulnerability a high rating, it noted how easily the flaw could be exploited.
Larry Ellison’s firm recommended IT departments update their systems as soon as possible, due to “the threat posed by a successful attack.”
Products affected include Oracle's Fusion Middleware and Application Server products. Oracle Enterprise Manager is also affected if the user is running the Fusion Middleware containing the vulnerability.
The flaw emerged last month, when the Apache Software Foundation revealed the denial-of-service vulnerability affected all versions of the Apache web server.
The Apache Software Foundation has already issued two patches to fix the problem in version 2.2.
“However conservative you might be, if you're an Oracle user, this patch is definitely recommended in a hurry,” said Sophos' Paul Ducklin, in a blog post.

Related links:
Attack tool published for Apache servers
Apache patches bug in its web server

برچسب‌ها