Due to customer feedback, Oracle has decided to provide the CVE numbers to individual patch mapping for the July 2010 Critical Patch Update, reports the Sun Security Community Security Blog. Initially, this was not available since this type of mapping is not Oracle policy; however, with its ears to the customers, the company decided to reinstitute this method, at least for this latest release of patches.
This policy is currently under evaluation and the security team wants to hear from customers regarding their need for the CVE and patch mapping disclosures before the October 2010 Critical Patch Update.
"In order to ensure that Oracle's new policy meets the needs of its customers, Oracle is asking assistance from its Solaris customers in formulating the policy pertaining to the CVE to patch mapping disclosures," the blog notes. "As such, I request that you contact me at derrick.scholl@oracle.com, or via secalert_us@oracle.com to help Oracle understand the specific requirements of your organization."
For the current July 2010 Critical Patch Update, mapping for the CVE numbers and Solaris patches are noted at this blog's Website.
More Information
July 2010 Critical Patch Update Released
[...read more...]
Other articles in the Security section of Volume 150, Issue 2:
Oracle to Provide the CVE Numbers to Individual Patch Mapping
(this article)
See all archived articles in the Security section.
|
|
Top 10 Most Popular Articles in Current Issue (Vol 167, Issue 4)
|
|
|
|
|
Recent Blog Entries as of February 4, 2012, 11:33 am |
|
|
|
|
|
|