CERT Advisory CA-2003-05

From: Jamie Andrews <nospam_at_linuxufo.com>
Date: 21 Feb 2003 02:56:23 -0800
Message-ID: <fd860813.0302210256.43fd3e3f_at_posting.google.com>


I have a couple of copies of Oracle 9i. Both are downloads from technet

The CERT Advisory ( http://www.cert.org/advisories/CA-2003-04.html ) says to fix them against these security bugs

However, actually applying the patches is problematic

Our software is in preproduction. We only need to run Oracle at this stage to test that it is compatible with other components. I am running Oracle at home as I am planning to take Oracle certification exams

The size of the downloads ( 3 CDs ) is big enough to be a problem for me. First on our online development server, there is a shortage of disk space. Unpacking everything could be quite tight. Second, my working environment is on an ISDN-2 dialup. Actually downloading the files would take days.

The patches are much smaller but I do not have a support identifier because these Oracle 9i copies are technet downloads.

See http://metalink.oracle.com/metalink_registration_faq.htm

I am used to using OSS software where patches are freely available, especially for security issues.

Is there an easier and less heavy route for fixing the CERT Advisory problems? Are the patches on metalink massive anyway? Comments please

Thanks Received on Fri Feb 21 2003 - 11:56:23 CET

Original text of this message