IT: Emergency Workaround For Oracle 0-Day 2008-07-29 23:04
Posted
by
kdawson
on Tuesday July 29, @11:04PM
from the maybe-somebody-shorted-the-stock dept.
from the maybe-somebody-shorted-the-stock dept.
Almost Live writes "Oracle has released an out-of-cycle alert to offer mitigation for a zero-day exploit that's been posted on the Internet. The emergency workaround addresses an unpatched remote buffer overflow that's remotely exploitable without the need for a username and password, and can result in compromising the confidentiality, integrity, and availability of the targeted system." Whoever published the vulnerability and matching exploit code did not contact Oracle first.

