ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Oracle pushes emergency DDoS vulnerability patch

Ellison's firm pushes out a rare out-of-cycle patch to fix a DDoS vulnerability.

By Tom Brewster, 19 Sep 2011 at 10:30

Patch

Oracle has issued an out-of-cycle patch for a denial of service flaw in the Apache web server, versions httpd 2.0 or 2.2, affecting a range of products.

Whilst Oracle has not given the vulnerability a high rating, it noted how easily the flaw could be exploited.

The general unwillingness of Oracle to deviate from its once-every-three-months patch cycle spells one word, ‘Importance.’

“This vulnerability may be remotely exploitable without authentication, i.e. it may be exploited over a network without the need for a username and password,” Oracle noted in its security advisory.

“A remote user can exploit this vulnerability to impact the availability of un-patched systems.”

Larry Ellison’s firm recommended IT departments update their systems as soon as possible, due to “the threat posed by a successful attack.”

Products affected include Oracle's Fusion Middleware and Application Server products. Oracle Enterprise Manager is also affected if the user is running the Fusion Middleware containing the vulnerability.

The flaw emerged last month, when the Apache Software Foundation revealed the denial-of-service vulnerability affected all versions of the Apache web server.

It worked by allowing a malicious user to exploit the Range feature in Apache web servers, which enables the pausing and resuming of downloads. An attack tool was spotted in the wild, giving hackers the power to overload a server by asking it to access multiple parts of a file simultaneously.

The Apache Software Foundation has already issued two patches to fix the problem in version 2.2. It sent out an initial patch towards the end of August, before issuing another to go on top of that fix.

“However conservative you might be, if you're an Oracle user, this patch is definitely recommended in a hurry,” said Sophos' Paul Ducklin, in a blog post.

“The general unwillingness of Oracle to deviate from its once-every-three-months patch cycle spells one word, ‘Importance.’”

Email to a friend

Print this page

< Previous   Web Servers : News

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

    Latest Web Servers Analysis & Insight

AWS instance starting

Amazon EC2’s Windows Server free version

Setting up a Windows server on Amazon's AWS is well within the reach of most IT pros, and it can even be free, Steve Cassidy discovers.

Read more

 

    Latest Web Servers Reviews

DeviceLock 7 review

Rating: 5

Accidental or deliberate data leakage is now a major security headache for businesses. Dave Mitchell takes a look at DeviceLock 7 to see if it plugs those holes that others leave behind.

Read more

 
advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement