{"id":689,"date":"2011-10-19T08:37:30","date_gmt":"2011-10-19T06:37:30","guid":{"rendered":"http:\/\/www.oradba.ch\/?p=689"},"modified":"2013-10-16T09:12:08","modified_gmt":"2013-10-16T07:12:08","slug":"update-oracle-released-cpu-psu-october-2011","status":"publish","type":"post","link":"https:\/\/www.oradba.ch\/wordpress\/2011\/10\/update-oracle-released-cpu-psu-october-2011\/","title":{"rendered":"Update: Oracle released CPU \/ PSU October 2011"},"content":{"rendered":"<p>Oracle has just officially released the CPU \/ PSU Patches for october 2011. In contrast to the <a href=\"https:\/\/www.oradba.ch\/wordpress\/2011\/10\/oracle-cpu-psu-pre-release-announcement-october-2011\/\" title=\"Oracle CPU \/ PSU Pre-Release Announcement October 2011\">previously announced 56 bug<\/a> fixes, there are now 57 bug fix. It looks like another bug fix for databases has been added to the CPU \/ PSU bundle. Never the less none of them is remote exploitable without authentication. None of these fixes are applicable to client-only installations. The maximum CVSS rating for the database vulnerabilities is still 6.5.<\/p>\n<p>The following Database Server Products are affected.<\/p>\n<ul>\n<li>Application Express<\/li>\n<li>Core RDBMS<\/li>\n<li>Database Vault<\/li>\n<li>Oracle Text<\/li>\n<\/ul>\n<p>As I mentioned in a previous post <a href=\"https:\/\/www.oradba.ch\/wordpress\/2011\/10\/oracle-cpu-psu-pre-release-announcement-october-2011\/\" title=\"Oracle CPU \/ PSU Pre-Release Announcement October 2011\" >Oracle CPU \/ PSU Pre-Release Announcement October 2011<\/a> the CPU \/ PSU patches are available for 10g and 11g. Whereby the download of 10g patches is only possible with a corresponding Extended Support contract. Brief overview of the available versions<\/p>\n<ul>\n<li><a href=\"https:\/\/support.oracle.com\/CSP\/main\/article?cmd=show&#038;type=NOT&#038;id=1346104.1#CHDHGEJG\">Oracle Database 11.2.0.3<\/a> => no CPU\/PSU bug fix are included in patchset<\/li>\n<li><a href=\"https:\/\/support.oracle.com\/CSP\/main\/article?cmd=show&#038;type=NOT&#038;id=1346104.1#CHDEBEJC\">Oracle Database 11.2.0.2<\/a> => normal CPU\/PSU<\/li>\n<li><a href=\"https:\/\/support.oracle.com\/CSP\/main\/article?cmd=show&#038;type=NOT&#038;id=1346104.1#CHDGJFBG\">Oracle Database 11.1.0.7<\/a> => normal CPU\/PSU<\/li>\n<li><a href=\"https:\/\/support.oracle.com\/CSP\/main\/article?cmd=show&#038;type=NOT&#038;id=1346104.1#BABECAJA\">Oracle Database 10.2.0.x<\/a> => Extended support contract required<\/li>\n<\/ul>\n<p>A bunch of useful links around the current CPU \/ PSU:<\/p>\n<ul>\n<li><a href=\"http:\/\/www.oracle.com\/technetwork\/topics\/security\/cpuoct2011-330135.html\">Oracle Critical Patch Update Advisory &#8211; October 2011<\/a><\/li>\n<li>Oracle Critical Patch Update October 2011 Documentation Map <em><a href=\"https:\/\/support.oracle.com\/CSP\/main\/article?cmd=show&#038;type=NOT&#038;id=1339643.1\">[ID 1339643.1]<\/a><\/em><\/li>\n<li>Patch Set Update and Critical Patch Update October 2011 Availability Document <em><a href=\"https:\/\/support.oracle.com\/CSP\/main\/article?cmd=show&#038;type=NOT&#038;id=1346104.1\">[ID 1346104.1]<\/a><\/em><\/li>\n<li>US-CERT <a href=\"http:\/\/www.us-cert.gov\/current\/archive\/2011\/10\/18\/archive.html#oracle_pre_release_announcements_for\">Oracle Releases Critical Patch Update for October 2011<\/a><\/li>\n<\/ul>\n<p>As well as a few generic links about CPU \/ PSU:<\/p>\n<ul>\n<li><a href=\"http:\/\/www.oracle.com\/technetwork\/topics\/security\/alerts-086861.html\">Critical Patch Updates and Security Alerts<\/a><\/li>\n<li>Release Schedule of Current Database Releases <em><a href=\"https:\/\/support.oracle.com\/CSP\/main\/article?cmd=show&#038;type=NOT&#038;id=742060.1\">[ID 742060.1]<\/a><\/em><\/li>\n<li>Risk Matrix Glossary &#8211; terms and definitions for Critical Patch Update risk matrices <em><a href=\"https:\/\/support.oracle.com\/CSP\/main\/article?cmd=show&#038;type=NOT&#038;id=394486.1\">[ID 394486.1]<\/a><\/em><\/li>\n<li>Use of Common Vulnerability Scoring System (CVSS) by Oracle <em><a href=\"https:\/\/support.oracle.com\/CSP\/main\/article?cmd=show&#038;type=NOT&#038;id=394487.1\">[ID 394487.1]<\/a><\/em><\/li>\n<li>DB, FMW, EM Grid Control, and OCS Software Error Correction Support Policy <em><a href=\"https:\/\/support.oracle.com\/CSP\/main\/article?cmd=show&#038;type=NOT&#038;id=209768.1\">[ID 209768.1<\/a>]<\/em><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Oracle has just officially released the CPU \/ PSU Patches for october 2011. In contrast to the previously announced 56 bug fixes, there are now 57 bugfix. It looks like another bug fix for databases has been added to the CPU \/ PSU bundle.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[6,7,8,46,114,11,116],"tags":[18],"class_list":["post-689","post","type-post","status-publish","format-standard","hentry","category-10gr2","category-11gr1","category-11gr2","category-cpu","category-psu-2","category-security","category-spu","tag-trivadiscontent"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p1aErb-b7","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":757,"url":"https:\/\/www.oradba.ch\/wordpress\/2012\/01\/update-oracle-released-cpu-psu-january-2012\/","url_meta":{"origin":689,"position":0},"title":"Update: Oracle released CPU \/ PSU January 2012","author":"Stefan","date":"24. January 2012","format":false,"excerpt":"Oracle has officially released the CPU \/ PSU Patches for january 2012. The Critical Patch Updates contains 78 security fixes across all products. But only two out of this 78 fixes are for Oracle databases.","rel":"","context":"In &quot;11gR1&quot;","block_context":{"text":"11gR1","link":"https:\/\/www.oradba.ch\/wordpress\/category\/oracle-database\/11gr1\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1505,"url":"https:\/\/www.oradba.ch\/wordpress\/2013\/10\/changes-in-database-security-patching-with-12c\/","url_meta":{"origin":689,"position":1},"title":"Changes in database security patching with 12c","author":"Stefan","date":"14. October 2013","format":false,"excerpt":"During my preparation for the tests of October Critical Patch Updates (CPU), I stumbled over an interesting Oracle Support Document. I this document Oracle announced that there will nolonger be seperate SPU (Security Patch Update) respectively CPU (Critical Patch Update) for 12.1.0.1 and newer. Excerpt from Oracle support document 1581950.1\u2026","rel":"","context":"In &quot;12cR1&quot;","block_context":{"text":"12cR1","link":"https:\/\/www.oradba.ch\/wordpress\/category\/oracle-database\/12cr1\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":2815,"url":"https:\/\/www.oradba.ch\/wordpress\/2018\/10\/oracle-cpu-psu-advisory-october-2018\/","url_meta":{"origin":689,"position":2},"title":"Oracle CPU \/ PSU Advisory October 2018","author":"Stefan","date":"22. October 2018","format":false,"excerpt":"Oracle has recently published the Critical Patch Update Advisory for the October 2018. It's once more quite a heavy update with not less than 301 security vulnerability fixes across the Oracle products. The Oracle database is relatively prominently represented with 3 security vulnerabilities and a maximal CVSS rating of 9.8.\u2026","rel":"","context":"In &quot;12R2&quot;","block_context":{"text":"12R2","link":"https:\/\/www.oradba.ch\/wordpress\/category\/oracle-database\/12r2\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":788,"url":"https:\/\/www.oradba.ch\/wordpress\/2012\/05\/important-links-around-the-oracle-cpu-psu-april-2012\/","url_meta":{"origin":689,"position":3},"title":"Important links around the Oracle CPU \/ PSU April 2012","author":"Stefan","date":"8. May 2012","format":false,"excerpt":"A few weeks ago oracle officially released the CPU \/ PSU Patches for April 2012. The Critical Patch Updates contains 88 security fixes across all products. But only 6 out of this 88 fixes are for Oracle databases. This post will summarize a bit the information and links around this\u2026","rel":"","context":"In &quot;Critical Patch Update&quot;","block_context":{"text":"Critical Patch Update","link":"https:\/\/www.oradba.ch\/wordpress\/category\/patches\/cpu\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1523,"url":"https:\/\/www.oradba.ch\/wordpress\/2013\/10\/oracle-released-cpu-psu-october-2013\/","url_meta":{"origin":689,"position":4},"title":"Oracle released CPU \/ PSU October 2013","author":"Stefan","date":"16. October 2013","format":false,"excerpt":"As announced yesterday in my post Oracle CPU \/ PSU Pre-Release Announcement October 2013, Oracle has now released the last Critical Patch Updates for 2013. Overall this CPU contains 126 new security fixes across several Oracle products like Database Server, MySQL Server, Sun Product Suite, WebLogic Server etc. For Oracle\u2026","rel":"","context":"In &quot;10gR2&quot;","block_context":{"text":"10gR2","link":"https:\/\/www.oradba.ch\/wordpress\/category\/oracle-database\/10gr2\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1680,"url":"https:\/\/www.oradba.ch\/wordpress\/2014\/04\/oracle-released-cpu-psu-april-2013\/","url_meta":{"origin":689,"position":5},"title":"Oracle released CPU \/ PSU April 2014","author":"Stefan","date":"16. April 2014","format":false,"excerpt":"As announced last week in my post Oracle CPU \/ PSU Pre-Release Announcement April 2014, Oracle has now released the Critical Patch Updates for April 2014. Overall this CPU contains 104 new security fixes across several Oracle products like Database Server, MySQL Server, Sun Product Suite, WebLogic Server etc. For\u2026","rel":"","context":"In &quot;11gR1&quot;","block_context":{"text":"11gR1","link":"https:\/\/www.oradba.ch\/wordpress\/category\/oracle-database\/11gr1\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"_links":{"self":[{"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/posts\/689","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/comments?post=689"}],"version-history":[{"count":3,"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/posts\/689\/revisions"}],"predecessor-version":[{"id":692,"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/posts\/689\/revisions\/692"}],"wp:attachment":[{"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/media?parent=689"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/categories?post=689"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oradba.ch\/wordpress\/wp-json\/wp\/v2\/tags?post=689"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}