Skip to content

Biting the hand that feeds IT

The Register ®

Security:


Related Whitepapers

Comments on ‘Zero-day bug hangs over Oracle database’

Forget about it

Published Friday 9th November 2007 14:33 GMT

« Back to article page

Great attitude guys! 

By Jason Evans
Posted Friday 9th November 2007 14:45 GMT
Thumb Down

So with all the flack that MS got from Oracle regarding security (including Oracle's Unbreakable campaign about 6 years ago), I think it's totally outrageous that Oracle's answer to fixing a security flaw is 'Yes we have resolved the problem, but we're not releasing the fix until next year.' - yeah, that's the way to win confidence in your customers lads!

So whilst admins are waiting for the fix, they will have plenty of anxious moments wondering if they are at risk from this bug.

At least MS has gotten their act together and release security patches often. Even if they do still get negative opinions about their software, at least they have listened to customer needs regarding software security.

NHS Spine upgrade to Oracle 10g 

By Anonymous Coward
Posted Friday 9th November 2007 15:09 GMT
Alert

Apparently, according to....

http://www.e-health-insider.com/news/3176/spine_to_be_shut_for_two_day_'refresh'

That link, the NHS are due to upgrade the SPINE to Oracle 10g at the end of this month.

That could be fun for privacy bods!

I'm not sure I want a "rushed" patch.... 

By Rob W
Posted Friday 9th November 2007 17:59 GMT

Yes, 2 months is a long time to wait for a patch. But I'm willing to wait.

Oracle has a much higher stability requirement than, say, Microsoft OS patches, or various web browsers. They have rigid patch release cycles because there are lots of steps involved in coding, checking, testing, etc. patches before they can make a release. They simply cannot hack a quick fix together in a day or two and throw it out there.

And frankly, how big of a risk is this? The Oracle database servers on projects that I've run would never be exposed to external access. And to EXPLOIT this vulnerability (to install malware on the server) the attacker must already be signed into the database... aren't you basically screwed anyway if you're letting unknown users get that far?

Ok... 

By Fraser
Posted Friday 9th November 2007 19:39 GMT

I reckon that we should start a good ol' fashioned my database is better than your database row, a la the MacOS, Windows, Linux rows.

Here are my starters for ten:

Oracle sucks, their security is bollox, you want to get yourself SQL Server, a modern database cheaper faster better.

Or

Oracle sucks, you want to get yourself DB2, runs on almost all hardware not like that sucky SQL server

Or

DB2? An old database for old men, who cares if it runs on Z OS.

Or

SQL Server? WFT? Why would you get a database that only runs on Winblows?

Zero dDay Opportunities. 

By amanfromMars
Posted Saturday 10th November 2007 08:45 GMT
Mars

"And to EXPLOIT this vulnerability (to install malware on the server) the attacker must already be signed into the database... aren't you basically screwed anyway if you're letting unknown users get that far?"

Who is saying that the users are unknown? They could be known unknowns that you didn't know you knew.

And to EXPLOIT the Zero dDay Opportunities, ignore them as malware at your Peril for who would be to say that it is not palware...... which would be perfectly consistent with known unknowns having got that far.

Pause....Ponder.... Promulgate Privately Pleases Parallel P.Irate* Programmers.

* Pretty Irate

DB holy war 

By Alan Donaly
Posted Sunday 11th November 2007 01:50 GMT
Thumb Up

No I can't t o o d u l l who cares.

Who gives a monkeys ? 

By Anonymous Coward
Posted Monday 12th November 2007 13:28 GMT
Coat

Must be a slow news day at El Reg ...

there is a bug - you can't get a patch until January - oh dear what can I do then ?

Answer : Nothing - so I can't get worked up about it.

Talk about alarmist nonsense.

whitepaper title

Gartner Paper: US Data Centers

U.S. enterprise data centers face considerable space and energy constraints over the next few years. Download this free independent report to read more..
whitepaper title

The Perfect (Virtual) Marriage

Get consistent virtual machine storage savings of 50% (often as high as 90%) with virtually no performance impact with NetApp deduplication..

Top 20 storiesAll The Week’s HeadlinesArchiveSearch