Slashdot Mirror


Oracle Patch Day Becoming Irrelevant

mocirac wak writes "Oracle's scheduled quarterly patch day is becoming more and more irrelevant. Oracle critical patches announced in the April 2006 CPU are still not available for download and the ETA is now set for May 15. The whole idea of a patch day was to let DBAs get prepared for testing and deployment. What's the use of having a patch day when there are no patches to download?" From the article: "... Oracle's explanation that patch testing is not yet done points to serious shortcomings and an absence of a good patch development process. 'For such a big organization with a lot of financial resources, they should be ready to handle this without problems. But they are amateurs on everything security related,' Cerrudo said. 'They spend a lot of time creating these patches. Then, patch day comes around and the patches aren't available. Then, when the patches are finally released, it's normal to find that they are incomplete and fail to address the actual vulnerability,' he added."

4 of 76 comments (clear)

  1. From TFA by Aqua_boy17 · · Score: 2, Funny

    "These aren't random complaints from unhappy researchers," Newman said, referring to the comments from Kornbrust and Cerrudo. "They need to admit their procedures aren't working and seek help getting it fixed."

    This Week on Ask Slashdot...

    'Larry' has a company that sells database software and he's trying to get developers to release security patches that are both trouble free and actually fix security holes and other problems...and then finally get them to do all of this on time.

    "Microsoft isn't good at security. We're good at that and I don't think sending a memo is going to help," 'Larry' states. Now he's turning to the /. community for help. So what advice can you give to 'Larry'?

    --
    What if the Hokey Pokey really is what it's all about?
    1. Re:From TFA by LearnToSpell · · Score: 2, Funny

      "Larry, have you tried PostgreSQL? It's fantastic, and free!"

  2. Is patch timing really an issue? by HarvardAce · · Score: 2, Funny
    Is the timing of the patches really that much of an issue? Do people install the patches as soon as they are released? I only ask because at my company we are about 2 years behind in the patches (we are still using 9i and in some cases 8), due to an inherent distrust of the stability of a patch. Likewise, not many people are in a rush to install the latest service packs of Windows until all the flaws are worked out.

    I could be missing the point here, and these are minor (yet critical) patches, but if they are, how come they are taking so much time to develop?

    --
    Note to self: Stop putting jokes in my insightful comments so I can get something other than +1 Funny!
  3. Unofficial patches by Matt+Perry · · Score: 4, Funny
    Unofficial patches available here: Mirror 1. Mirror 2.

    ;-)

    --
    Slashdot: Failed Car Analogies. Amateur Lawyering. Anecdote Battles.