Oracle 10g Critical Vulnerability Patch Withheld By Oracle
A buffer overflow has been found in Oracle 10g and a patch won’t be released until mid-January.
An attack requires authentication to the database, but assuming that, a successful exploit could execute code remotely. Proof-of-concept exploit code was posted on the Internet last Friday.
The best way to prevent this attack is tight network controls and monitoring database logs for unusual activity and logins.