Call: +44 (0)1904 557620 Call

Pete Finnigan's Oracle Security Weblog

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

[Previous entry: "Pete Finnigan is back after a week away from blogging!"] [Next entry: "Nice post about LOG ERRORS potential performance issue"]

CPU July 2005 and CPU October 2005 have problems!!

Oracle has sent out an email to all of the people who have downloaded either the July CPU 2005 or the October CPU 2005 for Oracle for Windows patches 21 and 23. A specific fix for a bug in OEM has not been applied. If you have not installed OEM then there is not an issue. If it is used then you need to download an interim patch 3570850. This fix will be included in for Windows in patch 24.

A copy of the email is reproduced below:

"Dear Oracle Customer,

You are receiving this email because our records indicated you
downloaded Critical Patch Update July 2005 (CPUJul2005) or October 2005
(CPUOct2005) patches for Oracle Database version Patch 21 (Patch
4437058) or Patch 23 (4554818) for the Windows platform.

Due to a patching error, a critical Windows specific fix related to
Oracle Enterprise Manager (OEM) is not included on the Windows patches.
If OEM was not installed, no action is required. If OEM was installed,
the 'Installed Products' option in the Oracle Universal Installer will
include "Oracle Enterprise Manager Products". In such case, to secure
your system from the vulnerabilities listed in CPUJul2005 and
CPUOct2005, please download and apply interim Patch 3570850, which can
be applied before or after Patch 21 or 23, and also 22. This critical
fix will be included in Oracle Database version Patch 24.

Please accept our apologies for any inconvenience you may have
experienced, and we thank you for your patience and cooperation in
securing your Oracle server products.

Oracle Global Product Support

P.S. Please do not reply to this email as this email account is not