[ news_security_news ] Oracle April Patches Pushed Into May
David Utter Staff Writer
2006-05-05
Insider Reports RSS Feed
April showers bring May flowers, but Oracle has been showered with criticism over its patch release woes; users of Oracle's various applications will have to wait until May 15th for the quarterly update that had been planned for April.
Compatibility issues or poor security practices? Oracle has delayed its most recent scheduled patch update by a month, and blamed the problem on application compatibility problems.
Oracle Security Alerts manager Darius Wiles said in an IDG report that some of those updates "failed out of the test suite, so we needed some more time to test them."
In order to ensure these updates work with its variety of product versions, notably Oracle databases 8.1.7.4 and 10.1.0.4. Updates for the databases have had a "bottleneck" effect on Oracle's ability to release additional updates.
One SecurityProNews reader joked in an email, "when I heard Oracle was going to offer Lifetime Support, I didn't realize they meant the length of time it would take to release the next set of patches."
Another Oracle observer was far more critical of the company. Mike Murray, Director of Vulnerability Research for nCircle, said in an email, "Larry Ellison and Mary Ann Davidson give a lot of lip service to security, but this shows that Oracle hasn't really committed the resources necessary to make security a priority and meet their commitments to customers.
"This is yet another example of Oracle's giving security the short shrift. Oracle has traditionally made security a B-level priority, and this newest slip is an example of how little they care about security as an operational discipline."
As Oracle pushes the April patches back, they risk running into the same issue again in July, when the next scheduled Critical Patch Update should take place.
---
Tag: Oracle
Add to | DiggThis | Yahoo! My Web | Furl It
Get all the updates in RSS:
About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.
More news_security_news Articles
Insider Reports RSS Feed
|
|