Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Usenet -> c.d.o.server -> Re: Where are the XE security patches?

Re: Where are the XE security patches?

From: joel garry <joel-garry_at_home.com>
Date: 13 Dec 2006 11:24:13 -0800
Message-ID: <1166037853.774830.114230@f1g2000cwa.googlegroups.com>

hpuxrac wrote:
> DA Morgan wrote:
> > DA Morgan wrote:
> > > hpuxrac wrote:
> > >> Pete Finnigan has got a very good point in his security blog
> > >> http://www.petefinnigan.com/weblog/entries/
> > >>
> > >> Perhaps it is disingenous of oracle to provide a free version of oracle
> > >> if there are not timely efforts to keep it patched and secured.
> > >
> > > Good point though I wouldn't have used the same words. I am checking on
> > > this and will report what I hear.
> >
> > I received one answer:
> >
> > The release of XE was delayed for four months so that Oracle could apply
> > and test a substantial number of security patches. If used per the docs
> > my source was unaware of any issues.
> >
> > The operative phrase here is "used per the docs" and not used for some
> > other purpose. Seems reasonable.
>
> If Pete Finnigan is hinting that there are unresolved security patches
> that currently haven't been applied against XE ... and oracle isn't
> committed to dates when it will be updated and patches ... that's
> "reasonable?".

It was my understanding when XE first came out ( as others noted http://groups.google.com/group/comp.databases.oracle.misc/msg/448ffb29b323d66b?dmode=source ) that the idea was for Oracle to handle all patching, and users would simply download and install the latest version when necessary. Seemed reasonable. Of course, I'm still using the beta, so how good is that going to work in practice anyways? Most users would probably stop fiddling once it got working.

>
> "My source was unaware of any issues?"
>
> Yikes.
>
> It don't take a weatherman to know which way the wind is blowing here.

Man I'm biting my tongue... let's just say, A Mighty Wind.

jg

--
@home.com is bogus.
http://www.signonsandiego.com/uniontrib/20061212/news_1b12ams.html
Received on Wed Dec 13 2006 - 13:24:13 CST

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US