By Jason EvansPosted Friday 9th November 2007 14:45 GMT
So with all the flack that MS got from Oracle regarding security (including Oracle's Unbreakable campaign about 6 years ago), I think it's totally outrageous that Oracle's answer to fixing a security flaw is 'Yes we have resolved the problem, but we're not releasing the fix until next year.' - yeah, that's the way to win confidence in your customers lads!
So whilst admins are waiting for the fix, they will have plenty of anxious moments wondering if they are at risk from this bug.
At least MS has gotten their act together and release security patches often. Even if they do still get negative opinions about their software, at least they have listened to customer needs regarding software security.
Yes, 2 months is a long time to wait for a patch. But I'm willing to wait.
Oracle has a much higher stability requirement than, say, Microsoft OS patches, or various web browsers. They have rigid patch release cycles because there are lots of steps involved in coding, checking, testing, etc. patches before they can make a release. They simply cannot hack a quick fix together in a day or two and throw it out there.
And frankly, how big of a risk is this? The Oracle database servers on projects that I've run would never be exposed to external access. And to EXPLOIT this vulnerability (to install malware on the server) the attacker must already be signed into the database... aren't you basically screwed anyway if you're letting unknown users get that far?
By amanfromMarsPosted Saturday 10th November 2007 08:45 GMT
"And to EXPLOIT this vulnerability (to install malware on the server) the attacker must already be signed into the database... aren't you basically screwed anyway if you're letting unknown users get that far?"
Who is saying that the users are unknown? They could be known unknowns that you didn't know you knew.
And to EXPLOIT the Zero dDay Opportunities, ignore them as malware at your Peril for who would be to say that it is not palware...... which would be perfectly consistent with known unknowns having got that far.
Comments on: Zero-day bug hangs over Oracle database
Great attitude guys! #
By Jason Evans Posted Friday 9th November 2007 14:45 GMT
NHS Spine upgrade to Oracle 10g #
By Anonymous Coward Posted Friday 9th November 2007 15:09 GMT
I'm not sure I want a "rushed" patch.... #
By Rob W Posted Friday 9th November 2007 17:59 GMT
Ok... #
By Fraser Posted Friday 9th November 2007 19:39 GMT
Zero dDay Opportunities. #
By amanfromMars Posted Saturday 10th November 2007 08:45 GMT
DB holy war #
By Alan Donaly Posted Sunday 11th November 2007 01:50 GMT
Who gives a monkeys ? #
By Anonymous Coward Posted Monday 12th November 2007 13:28 GMT