Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
Security Java Oracle

Oracle Patches 136 Flaws In 49 Products 23

An anonymous reader writes: Oracle has released the April 2016 Critical Patch Update, which provides fixes for 136 vulnerabilities in 49 products, including Java SE and MySQL, the company's Database Server and E-Business Suite, its Fusion Middleware, and its Sun Systems Products Suite. "Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released fixes. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply Critical Patch Update fixes without delay," the company advised.
This discussion has been archived. No new comments can be posted.

Oracle Patches 136 Flaws In 49 Products

Comments Filter:
  • and not completely terrible at it, only moderately bad.

    I do like how they managed to call their customers idiots in the same announcement.
  • ... and in doing so, introduces 243 bugs.

    • by Anonymous Coward

      99 bugs in the code, 99 bugs in the code. Take one down, patch it around 127 bugs in the code

  • I mean, does ask.com exist outside of people who updated Java searching how to make it go back to whatever they already had?

  • by ErichTheRed ( 39327 ) on Wednesday April 20, 2016 @01:31PM (#51949733)

    Define "Actively Supported," Oracle.

    I work in an industry whose IT ecosystem has lots of legacy baggage, and has strata of old systems that can be pinpointed to Programming Fad of the Year in the year they were built. Worse yet, my specialty is end user stuff, so my job lately has been to try to clean some of this up. We've got insanely complex Java applets, lots of really old Flash web stuff, Visual Basic 6 that heavily relies on towers of COM+ libraries, web apps that use every single quirk of IE 6, massive ActiveX applications that require scary levels of local permissions to function, and so on. To make it fun, the nature of our industry is such that these are mostly bespoke, one off applications written by companies that don't exist anymore, people we can't find, or consultancies that want millions of dollars for upgrades. Getting this all working on modern systems is a huge challenge, especially when your new normal is supporting non-quirky applications from the present day that are pretty well behaved.

    Oracle doesn't make this any easier by not patching flaws in older JREs or other software if you don't pay for extended support. In fact, one issue I had that's thankfully gone now was Oracle's own financial product relying on Oracle's own recompiled JRE (the "JInitiator." Under the covers, Oracle still is patching these security holes for customers who pay an exorbitant license fee to run the "free" client side JRE. They don't release them to the public, ostensibly to get consumers to upgrade, but we know the real reason.

    I know companies can't support software forever, but the previous (pre Sun/Oracle merger) environment encouraged client side Java use by giving away the JRE and JDK for free and keeping them patched. Now, applets and browser plugins are a bad idea, everyone realizes this now. But software from the early to mod 2000s relies heavily on them.

    • by guruevi ( 827432 )

      And at what point do your clients realize that all of the above behavior by companies can be avoided by simply using/writing open source solutions?

      • Comment removed based on user account deletion
        • by guruevi ( 827432 )

          At least you'll have access to the source code and can give it to a new contractor for further work/fixes. The main problem as GP states is that you get binaries from organizations that either no longer exist or turn into extortionists to fix anything. If you have the source, at least that is no longer a valid excuse.

    • I work in an industry whose IT ecosystem has lots of legacy baggage, and has strata of old systems that can be pinpointed to Programming Fad of the Year in the year they were built.

      That's awfully non-specific because this applies to, like, all of them.

    • They don't release them to the public, ostensibly to get consumers to upgrade, but we know the real reason.

      We do indeed: they want customers to upgrade. There is no reason to expect otherwise - it is common practice that SW companies don't want to have to keep patching old versions, because 1) there is a new version in which the flaws are being fixed, and people should upgrade, and 2) it is an expense that you get no reward for. I think it is perfectly reasonable that you only want to do this work, if you are payed - many companies won't, even for good money.

  • by idbeholda ( 2405958 ) on Wednesday April 20, 2016 @01:44PM (#51949877) Journal
    Notepad is still the current reigning champion of being exploit-free since 1985.
    • It's funny you mention that, but it makes sense. Simple software with simple features is hard to screw up security-wise. Abstraction, feature bloat, relying on massive third-party libraries you don't control, etc. are usually the root cause of these problems.

      Then again, in the Windows world, once in a while an exploit comes completely out of left field. I think a few years ago there was a patch for Windows Paint of all things, and an exploit in the code for the font subsystem. Talk about stuff that never ch

    • by guruevi ( 827432 )

      You forgot all about: CVE-2011-1991 and there must have been several others but I can't be bothered to look it up. Try opening Notepad with a debugger attached, you see all kinds of crap being loaded including IE stuff.

    • Notepad you say? Open that 8tb backup image in notepad some time. go on, i'll wait. and wait. and wait. ....
  • by darkain ( 749283 ) on Wednesday April 20, 2016 @04:07PM (#51951215) Homepage

    Good thing I already installed the patch for Oracle MySQL, it is called MariaDB!

One person's error is another person's data.

Working...