Oracle patch batch eclipses Microsoft Patch Tuesday
41 to one
Posted in Enterprise Security, 9th January 2009 11:31 GMT
Free whitepaper – Avoiding 7 common mistakes of IT security compliance
Next Tuesday (13 January) promises to be a busy day for hard-pressed sys admins.
Although Microsoft's regular monthly Patch Tuesday update promises only one bulletin, a critical fix for Windows1, Oracle's quarterly batch weighs in at 41 fixes.
The updates fix vulnerabilities across "hundreds of Oracle products", an alert from Oracle warns.
Highlights include nine critical bug fixes for Oracle Secure Backup, all of which might lend themselves to remote exploitation, and two critical fixes for Oracle Application Server. There's also five critical updates for Oracle BEA WebLogic server software packages.
Ten of the remaining (less critical) bulletins address lower-risk flaws in various versions of Oracle's database server software.
Oracle's pre-alert, which explains the planned patches in much greater depth, can be found here.
1 Microsoft light sprinkle of patches means that a flaw in SQL Server, which became the target of exploit code soon after the December 2008 patch Tuesday update, will remain unaddressed for at least another month. ®
Free whitepaper – Certify your software integrity with Thawte code signing certificates


The best practices guide for application security
Reducing messaging and web security costs with managed services
Avoiding 7 common mistakes of IT security compliance
Certify your software integrity with Thawte code signing certificates
The future of SaaS and IT infrastructure management
Feds: Hospital hacker's 'massive' DDoS averted
Microsoft knew of nasty IE bug a year before attacks
BlockMaster SafeStick hardware-encrypted USB drive