ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

65 security holes found in Oracle

Joris Evers CNET News.com

Published: 19 Jul 2006 09:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

On Tuesday, as part of its quarterly patch cycle, Oracle released fixes for 65 security vulnerabilities that affect many of its products.

Many of the vulnerabilities are significant; 27 of the 65 bugs could be exploited remotely by an anonymous attacker, Darius Wiles, senior manager for security alerts at Oracle, said in an interview. Oracle has no suggested workarounds for any of the issues. Instead it is urging customers to patch their systems.

"We fix flaws in severity order. The fixes you see in the Critical Patch Update are the most critical," Wiles said. "We strongly recommend to customers that they apply these security patches as soon as they can."

Oracle's July Critical Patch Update delivers remedies for 23 flaws related to Oracle's Database products, one related to the Collaboration Suite, 10 in Application Server, 20 related to E-Business Suite and Applications, four in the Enterprise Manager, two in PeopleSoft's Enterprise portal and one in JD Edwards software.

In addition, the patch bunch includes fixes for four security vulnerabilities in client software that works with the Oracle database. This is only the second time since Oracle started releasing its Critical Patch Update, or CPU, in January 2005 that it has included fixes for software that runs on PCs, not servers.

"Customers need to think about patching desktops for the July CPU, whereas in the majority of CPUs only the database server needs to be patched," Wiles said.

Three of the four flaws in the client software are considered to be severe because they don't require any authentication and can be exploited remotely, according to Oracle's security alert.

One of the new Oracle fixes repairs a database vulnerability the company accidentally detailed in April. Usually secretive about security and critical of researchers who publicly discuss flaws in Oracle products, on 6 April the company published a note on its MetaLink customer Web site with details about the unfixed flaw.

In April, Oracle faced criticism for not delivering patches for all its products at the same time. The company is looking to improve on that this time around. "Our aim is to deliver quality patches on the official day of release," Wiles said.

The July patch release should include about 250 software fixes for Oracle products on multiple operating system platforms. Of those, approximately 10 are not available yet, but will be in the coming days. Some might take a bit longer, Wiles said.

Oracle is not aware of any attacks that exploit the flaws addressed in its Critical Patch Update, Wiles said. The company, which has been criticised for its slowness in patching flaws reported by security researchers, is still working on issues that have been brought to its attention and plans to address those in later patch releases, he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
76 out of 148 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

COBOL Mainframe Developer/Support Analyst - Contract - Nottingham

Your responsibilities will include developing bug fixes, patches and system upgrades as well as supporting external clients in line with agreed ...

Oracle DBA with proven track record, 6 month contract based NW London

Relevant experience of Oracle RDBMS, upgrades and patching, performance tuning, RMAN and Backup and Recovery solutions. A prestigious company who has ...

Seeking Oracle Database Professional- london 55k

Seeking Professional Database Professional for fantastic opportunity in London- interviewing immediately! The role requires an experienced Oracle ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation