Oracle posts quarterly patch bundle

Enterprise computing giant Oracle patches up thirty vulnerabilities with latest fix bundle

Written by Martin Veitch

Oracle has posted its latest quarterly Critical Patch Update covering over 30 vulnerabilities, including a much publicised problem that was the cause of a dispute early this year.

Some experts, most notably David Litchfield of NGS Software, a UK-based security specialist, have accused the database giant of tardiness in patching critical flaws.

In January, Litchfield described a “very, very serious” issue with the PL/SQL Gateway, which he said would allow an attacker complete control of a back-end database server. At the time, Oracle reportedly criticised Litchfield for disclosing the problem publicly, played down the seriousness of the issue and said NGS’s workaround could harm other Oracle software.

Despite the spat, Litchfield is credited by Oracle in the update as one of those who “discovered and brought security vulnerabilities … to Oracle’s attention”. He was not immediately available for comment.

Some experts noted that some of the patches in the update would not be available on all platforms until the end of the month. The next Critical Path Update is due on 18 July.

In a recent report, Forrester Research analyst Noel Yuhanna suggested that database security was often overlooked in favour of perimeter security.

“DBMS [database management system] security is not about software or hardware; it’s about establishing solid security policies and procedures and ensuring that they are supported by the DBMS security infrastructure and are well integrated with other elements of IT security,” Yuhanna wrote.

Tags:

reader comments

related articles

In 2005 nearly nine out of 10 of UK companies installed security updates within a week of issue

British business picks up on patching

But still slow on antivirus signatures, finds DTI survey 01 Mar 2006

 

Sun shines on patch management buy

Unix giant buys Solaris and Linux update software firm 23 Feb 2006

Hackers look to applications

Hacking operating systems is so last year 23 Nov 2005

Experts warn that firms are mishandling web security

Protecting the network means nothing if applications are vulnerable, warns consultancy 22 Feb 2006

Gartner slams Oracle security processes

Firm's software 'can no longer be considered a bastion of security', claims analyst 26 Jan 2006

Major DNS flaw revealed

Experts sound alarms over early disclosure 23 Jul 2008

Infosecurity Europe show to focus on data breaches

Annual trade show will see the launch of the annual Information Security Breaches Survey 17 Apr 2008

Image-applet combo hack revealed

Hybrid file can hijack browsers looking at uploaded images 04 Aug 2008

related whitepapers

today's top stories

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

City in pressing need of skilled IT matchmakers

With the financial services sector plunging ever deeper into an M&A maelstrom, IT leaders are having their systems integration skills and due diligence expertise tested as never before 09 Oct 2008

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Podcast imageAudio

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Latest in-depth articles

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Comment

Broadband must be a spending priority

For the economic health of the nation, the government would do better to bankroll an optical fibre rollout rather than prop up profligate banks 09 Oct 2008

Advertisement

Primary Navigation