Oracle rushes out emergency Apache DoS patch
Sysadmins shouldn't hang about with this one...
Regcast training : Hyper-V 3.0, VM high availability and disaster recovery
Oracle broke with tradition with the publication of an unscheduled security update last weekend.
The fix – which addresses a DoS vulnerability in its Apache web server software – represents only the fifth time that Oracle has published a security fix outside the quarterly patch update batch it began at the start of 2005, net security firm Sophos notes. More specifically the patch provides an updated Apache web server, httpd, to Oracle's Fusion Middleware and Application Server products. The former product includes Apache httpd 2.2; the latter includes Apache httpd 2.0.
The vulnerability, CVE-2011-3192, creates a means to trick a web clients into requesting multiple parts of the same file at the same time, causing systems to get hopelessly tied up in knots and crash. The Apache Foundation addressed the same underlying byte-range flaw first with an 2.2.20 update at the end of August. Last week it ironed out glitches in this bug fix with a further update, 2.2.21.
It isn't clear which code base Oracle has used, although giving testing schedules and the like, the earlier (imperfect) patch seems more likely. Whatever code base it has used, Oracle is emphatic that sysadmins need to apply the patch sooner rather than later. "Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Security Alert fixes as soon as possible," it said. ®
COMMENTS
shouldn't that have said 'forwarded' or 'relayed'
I belive Apache et al did all of the rushing.
In journo-talk, you simply add another 'D' if its really really bad.
DoS == Bad vulnerability
DDoS == Double bad vulnerability
Are they charging for this too?
Are the oracle-scum charging for this as usual, got to buy a MOS account and pay the fine for this criminal negligence?

IT infrastructure monitoring strategies
Agentless Backup is Not a Myth
Top 10 SIEM implementer’s checklist
Steps to Take Before Choosing a Business Continuity Partner
Requirements Checklist for Choosing a Cloud Backup and Recovery Service Provider