You are here: silicon.com > Software > Security Strategy

Security Strategy

Fixes for 33 flaws: Oracle goes patch-tastic

'You are really spoiling us... '

Tags: flaw, patch, oracle

By Joris Evers

Published: 19 October 2005 08:50 BST

Oracle on Tuesday released fixes for a laundry list of security vulnerabilities in many of its software products.

The "Critical Patch Update", part of Oracle's quarterly patch release cycle, delivers fixes for 33 flaws in Oracle's Database products, 14 in its Application Server, 13 in the Collaboration Suite, 22 in E-Business Suite and Applications, four in PeopleSoft's PeopleTools, and two in JD Edwards software.

Several of the flaws carry Oracle's most serious rating, which means they are easy to exploit and an attack can have a wide impact, according to the alert. Symantec said in an alert to users of its DeepSight intelligence service: "The most severe of the vulnerabilities could possibly expose affected computers to complete compromise."

Oracle doesn't provide many details in its advisory, which could be a challenge for users when prioritising patches, Pete Finnigan, a security specialist, wrote on his blog. "The descriptions for all the bugs except for the database section give nothing away whatsoever," he said.

Oracle has been criticised for dragging its heels on fixing security flaws and being unresponsive to researchers who find bugs. In response, Oracle's chief security officer, Mary Ann Davidson, said security researchers can be a problem when it comes to product security.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
TWS Scheduling Specialist - UNIX AIX/TRU64, Windows O/S, MS Office, Shell - St Davids Park, Ewloe, Deeside

Provide 2nd level infrastructure support as required - Undertake the diagnosis and completion of Root Cause Analyses to enable Problem Management as ...

Websphere IT Specialist / Architect

Trouble shoot and fix technical problems, liaising with product management and technical support to organise a patch if necessary. Understand and be ...

Oracle DBA with UNIX Immediate Vacancy London/ Croydon 35k

The role is to provide day to day support, troubleshooting, tuning, administration, systems hardening (security), and project work for a wide range ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: