59 Security bugs fixed, 28 remotely expolitable, 13 in the database
There has been 4 Comments posted on this article
July 21st, 2010 at 11:14 pm
Pete Finnigan says:
Hello Pete:
I found your blog while googling about Oracle Security Updates. We are new to Oracle and have Oracle 10.2.0.1. We would like to apply security updates but cannot get a straight answer on how to do this when our version is not listed. Do we have to upgrade to 10.2.0.4 and then apply the patches? Are there best practices for applying these patches? Thank you in advance. Debbie Nelson, AGA Medical
July 22nd, 2010 at 01:30 pm
Pete Finnigan says:
Hi Debbie,
Thanks for your question.
Yes you are right there are no security critical patch updates for unsupported versions (for security patches) of Oracle.
The only way to apply a security patch is to upgrade to the latest supported (for security patches) patch set.
The latest patch set (depending on when you get it) will have the latest CPU fixes in it and cumulatively all that came before. So depending on your timing you may also need to download and apply the latest CPU.
hth
Pete
July 15th, 2010 at 02:04 am
Pete Finnigan says:
Hi Pete,
I believe that the number of names credited is directly related to the fact that the security advisory includes a whole new family of Sun products.