The bug, which Oracle reported as fixed in the most recent Critical Patch Update, is only fixed in upcoming versions of the database, not in currently shipping releases. The vulnerability lies in the TNS Listener service, which on Oracle databases functions as the service that routes connection requests from clients to the server itself. A researcher named Joxean Koret said that he discovered the vulnerability several years ago and then sold the details of the bug to a third party broker, who reported it to Oracle in 2008.
Source: https://threatpost.com/critical-bug-reported-oracle-servers-042612/76491/

