Oracle Security Alert for CVE-2012-1675 (TNS Listener Poison Attack)
Dears,
I am running Oracle with the following environments :
- 10.2.0.5 under IBM AIX 64
- 10.2.0.5 under HP UX (ia64)
- 10.2.0.5 under Windows Server 2008 R2 (x64 bit)
- 10.2.0.4 under Linux x86
I read the new security alert from Oracle about Listener Posion Attack (Note 1453883.1).
I am not using RAC.
This note requires to add COST parameter to the listener.ora.
But my question is : For the above releases, is it required to apply the patch 12880299 before doing this change in Listener.ora
If yes, why I cannot see through the Metalink the availability of this patch for envirronments NON RAC
(All what I found is RAC: TCP HANDLERS BLOCK IF LISTENER REGISTRATION IS RESTRICTED TO IPC W/COST (Patch))