{"id":1523,"date":"2013-10-16T21:49:13","date_gmt":"2013-10-16T19:49:13","guid":{"rendered":"http:\/\/www.oradba.ch\/?p=1523"},"modified":"2013-10-16T22:36:43","modified_gmt":"2013-10-16T20:36:43","slug":"oracle-released-cpu-psu-october-2013","status":"publish","type":"post","link":"https:\/\/www.oradba.ch\/wordpress\/2013\/10\/oracle-released-cpu-psu-october-2013\/","title":{"rendered":"Oracle released CPU \/ PSU October 2013"},"content":{"rendered":"<p>As announced yesterday in my post <a href=\"https:\/\/www.oradba.ch\/wordpress\/2013\/10\/oracle-cpu-psu-pre-release-announcement-october-2013\/\" target=\"_blank\">Oracle CPU \/ PSU Pre-Release Announcement October 2013<\/a>, Oracle has now released the last Critical Patch Updates for 2013. Overall this CPU contains 126 new security fixes across several Oracle products like Database Server, MySQL Server, Sun Product Suite, WebLogic Server etc. For Oracle Database it contains only 2 security fixes with a rather medium CVSS rating. Although the Core RDBMS is affected, it is probably not necessary to run a fire drill. If you have planned to patch anyway, it makes sense to consider the latest PSU or SRU. And if you plan to install <a href=\"https:\/\/www.oradba.ch\/wordpress\/2013\/08\/oracle-11-2-0-4-0-patchset-released\/\" title=\"Oracle 11.2.0.4.0 Patchset released\" target=\"_blank\">Oracle 11.2.0.4.0 patch set<\/a>, this critical patch update can even be skip, since there is no PSU or SPU for 11.2.0.4 available. According to the patch read-me, it seems that CVE-2013-5771 is fixed in 11.2.0.4. But I can&#8217;t confirm this, because I could not find a Bug-ID to compare.<\/p>\n<p>By the way, Oracle has changed a few thing in <a href=\"https:\/\/www.oradba.ch\/wordpress\/2013\/10\/changes-in-database-security-patching-with-12c\/\" title=\"Changes in database security patching with 12c\" target=\"_blank\">database security patching for 12c<\/a>. They will not publish any separate security patch updates (SPU) anymore but solely patch set update (PSU)<\/p>\n<h3>CPU Release Dates<\/h3>\n<p>The next four Critical Patch Updates will be released at the following dates:<\/p>\n<ul>\n<li>14 January 2014<\/li>\n<li>15 April 2014<\/li>\n<li>15 July 2014<\/li>\n<li>14 October 2014<\/li>\n<\/ul>\n<h3>References<\/h3>\n<p>Links all around Critical Patch Update:<\/p>\n<ul>\n<li><a href=\"http:\/\/www.oracle.com\/technetwork\/topics\/security\/cpuoct2013-1899837.html\" target=\"_blank\">Oracle Critical Patch Update Advisory &#8211; October 2013<\/a><\/li>\n<li>Patch Set Update and Critical Patch Update October 2013 Availability Document [<em><a href=\"https:\/\/support.oracle.com\/epmos\/faces\/DocumentDisplay?id=1571391.1\" target=\"_blank\">1571391.1<\/a><\/em>]<\/li>\n<li>Oracle Critical Patch Update October 2013 Documentation Map [<em><a href=\"https:\/\/support.oracle.com\/epmos\/faces\/DocumentDisplay?id=1569424.1\" target=\"_blank\">1569424.1<\/a><\/em>]<\/li>\n<li>Critical Patch Update October 2013 Database Known Issues [<em><a href=\"https:\/\/support.oracle.com\/epmos\/faces\/DocumentDisplay?id=1571655.1\" target=\"_blank\">1571655.1<\/a><\/em>]<\/li>\n<li>Critical Patch October 2013 Database Patch Security Vulnerability Molecule Mapping [<em><a href=\"https:\/\/support.oracle.com\/epmos\/faces\/DocumentDisplay?id=1571653.1\" target=\"_blank\">1571653.1<\/a><\/em>]<\/li>\n<li>Oracle Critical Patch Updates and Security Alerts on <a href=\"http:\/\/www.oracle.com\/technetwork\/topics\/security\/alerts-086861.html\" target=\"_blank\">OTN<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>As announced yesterday in my post Oracle CPU \/ PSU Pre-Release Announcement October 2013, Oracle has now released the last Critical Patch Updates for 2013. Overall this CPU contains 126 new security fixes across several Oracle products like Database Server, MySQL Server, Sun Product Suite, WebLogic Server etc. For Oracle Database it contains only 2 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[6,7,8,83,46,5,114,11,116],"tags":[111],"class_list":["post-1523","post","type-post","status-publish","format-standard","hentry","category-10gr2","category-11gr1","category-11gr2","category-12cr1","category-cpu","category-oracle-database","category-psu-2","category-security","category-spu","tag-tvdsecexpert"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p1aErb-oz","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":683,"url":"https:\/\/www.oradba.ch\/wordpress\/2011\/10\/oracle-cpu-psu-pre-release-announcement-october-2011\/","url_meta":{"origin":1523,"position":0},"title":"Oracle CPU \/ PSU Pre-Release Announcement October 2011","author":"Stefan","date":"14. October 2011","format":false,"excerpt":"Oracle has recently published the Pre-Release Announcement for the CPU Patch. This Critical Patch Update contains 56 new security vulnerability fixes for several Oracle products. 4 of these fixes are just for the Oracle Database Server.","rel":"","context":"In &quot;10gR2&quot;","block_context":{"text":"10gR2","link":"https:\/\/www.oradba.ch\/wordpress\/category\/oracle-database\/10gr2\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":757,"url":"https:\/\/www.oradba.ch\/wordpress\/2012\/01\/update-oracle-released-cpu-psu-january-2012\/","url_meta":{"origin":1523,"position":1},"title":"Update: Oracle released CPU \/ PSU January 2012","author":"Stefan","date":"24. January 2012","format":false,"excerpt":"Oracle has officially released the CPU \/ PSU Patches for january 2012. The Critical Patch Updates contains 78 security fixes across all products. But only two out of this 78 fixes are for Oracle databases.","rel":"","context":"In &quot;11gR1&quot;","block_context":{"text":"11gR1","link":"https:\/\/www.oradba.ch\/wordpress\/category\/oracle-database\/11gr1\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":878,"url":"https:\/\/www.oradba.ch\/wordpress\/2012\/10\/oracle-cpu-psu-pre-release-announcement-october-2012\/","url_meta":{"origin":1523,"position":2},"title":"Oracle CPU \/ PSU Pre-Release Announcement October 2012","author":"Stefan","date":"12. October 2012","format":false,"excerpt":"Today Oracle has published the Pre-Release Announcement for the october CPU Patch. This Critical Patch Update contains 109 new security vulnerability fixes for several Oracle products. 5 of these fixes are just for the Oracle Database Server.","rel":"","context":"In &quot;10gR2&quot;","block_context":{"text":"10gR2","link":"https:\/\/www.oradba.ch\/wordpress\/category\/oracle-database\/10gr2\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1680,"url":"https:\/\/www.oradba.ch\/wordpress\/2014\/04\/oracle-released-cpu-psu-april-2013\/","url_meta":{"origin":1523,"position":3},"title":"Oracle released CPU \/ PSU April 2014","author":"Stefan","date":"16. April 2014","format":false,"excerpt":"As announced last week in my post Oracle CPU \/ PSU Pre-Release Announcement April 2014, Oracle has now released the Critical Patch Updates for April 2014. Overall this CPU contains 104 new security fixes across several Oracle products like Database Server, MySQL Server, Sun Product Suite, WebLogic Server etc. For\u2026","rel":"","context":"In &quot;11gR1&quot;","block_context":{"text":"11gR1","link":"https:\/\/www.oradba.ch\/wordpress\/category\/oracle-database\/11gr1\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":983,"url":"https:\/\/www.oradba.ch\/wordpress\/2013\/01\/oracle-released-cpu-psu-january-2013\/","url_meta":{"origin":1523,"position":4},"title":"Oracle released CPU \/ PSU January 2013","author":"Stefan","date":"16. January 2013","format":false,"excerpt":"As announced in my post about Oracle's pre-release announcement of last week, Oracle has now released the first Critical Patch Updates for 2013. Overall this CPU contains 86 new security fixes across several Oracle products like Database Server, MySQL Server, Sun Product Suite, WebLogic Server etc. For products like Oracle\u2026","rel":"","context":"In &quot;Critical Patch Update&quot;","block_context":{"text":"Critical Patch Update","link":"https:\/\/www.oradba.ch\/wordpress\/category\/patches\/cpu\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1501,"url":"https:\/\/www.oradba.ch\/wordpress\/2013\/10\/oracle-cpu-psu-pre-release-announcement-october-2013\/","url_meta":{"origin":1523,"position":5},"title":"Oracle CPU \/ PSU Pre-Release Announcement October 2013","author":"Stefan","date":"14. October 2013","format":false,"excerpt":"Oracle has published the Pre-Release Announcement for the October CPU\/SPU Patch. This Critical Patch Update contains 126 new security vulnerability fixes for several Oracle products. Despite the large amount of security fixes, it is a rather small update from the database point of view. There are only two security fix\u2026","rel":"","context":"In &quot;11gR2&quot;","block_context":{"text":"11gR2","link":"https:\/\/www.oradba.ch\/wordpress\/category\/oracle-database\/11gr2\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"_links":{"self":[{"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/posts\/1523","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/comments?post=1523"}],"version-history":[{"count":3,"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/posts\/1523\/revisions"}],"predecessor-version":[{"id":1526,"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/posts\/1523\/revisions\/1526"}],"wp:attachment":[{"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/media?parent=1523"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/categories?post=1523"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/tags?post=1523"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}