The advisory has been updated recently.
The updated advisory includes answers to your questions.
The ACL mentioned initially in the advisory has been modified from the initial suggested workaround to include suggestions for specific denies of certain IP protocols and a permit ip any any at the end.
Please refer to the same link above for further details.
peter