Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Microsoft, Oracle issue patches for slew of holes

April 20, 2009 12:00 PM ET

Computerworld - Microsoft Corp. last week released eight security updates that patch 23 vulnerabilities in Windows, Internet Explorer, Excel and other software products in the company's portfolio.

Analysts noted that even more dangerous than the unusually large number of patches is the fact that nearly half of them fix flaws that have already been or can be exploited by hackers.

"What really caught our eye is the large number of exploits that are already available," said Wolfgang Kandek, chief technology officer at Qualys Inc., a provider of on-demand security tools. "Out of the 23, there are 10 exploits or [flaws] that have proof of concept."

"You could call this a spring cleaning," said Eric Schultze, CTO at Shavlik Technologies LLC, a network security vendor. "Microsoft jumped on a couple of zero-days, including Excel from February and WordPad from last December. It's nice to see those taken care of."

Kandek and Amol Sarwate, manager of the vulnerability research lab at Qualys, recommended that users first patch the 10 flaws that have known exploits by applying the "critical" updates for Excel and WordPad, and an "important" patch designed to fix the so-called token-kidnapping issues in Windows. "Critical" and "important" are the top two rankings in Microsoft's four-step threat-scoring system.

Meanwhile, Oracle Corp. last week released 43 security fixes for a range of products, including its flagship database and the Oracle Application Server. The patches also fix flaws in its E-Business Suite and PeopleSoft Enterprise applications, and its WebLogic application server.

Oracle said that 16 of the patches are for various database versions. The most severe vulnerability, which affects Versions 9.2.0.8 and 9.2.0.8DV, "can potentially allow an attacker to gain full control of a vulnerable server," according to a post on Oracle's global product security blog.

The update also includes patches for eight vulnerabilities in Oracle's WebLogic and AquaLogic products, including JRockit, and for WebLogic Server plug-ins for Apache and IIS Web servers, according to the blog post.

This version of the story originally appeared in Computerworld's print edition.

Read more about security in Computerworld's Security Knowledge Center.



Jump to comments

microsoft

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs