oss-sec mailing list archives
Re: [External] : Fwd: [oss-security] Oracle January 2025 Critical Patch Update
From: Bruce Lowenthal <bruce.lowenthal () oracle com>
Date: Thu, 23 Jan 2025 06:47:29 -0800
Olle, Solar Designer, oss-security list:I am responsible for the content and publication of Oracle Critical Patch Updates. These are published quarterly in three formats: Tabular format HTML "AKA risk matrix", English Language HTML format and Oasis Standard CSAF format via references at Oracle's Critical Patch Updates, Security Alerts and Bulletins home page at
* https://www.oracle.com/security-alerts/This home page references individual quarterly reports and provides other information regarding our security program. In addition, that page provides instructions allowing anyone to sign up to receive eMail announcing when Oracle Critical Patch Updates and other security advisories are published. See:
* Instructions for subscribing to email notifications <https://www.oracle.com/security-alerts/securityemail.html>of Critical Patch Update Advisories and Security Alerts. If you have any questions, feel free to contact me directly. Bruce ----- On 1/22/25 11:50 PM, Olle E. Johansson wrote:
Bruce, For your information. /OBegin forwarded message: *From: *Solar Designer <solar () openwall com> *Subject: **[oss-security] Oracle January 2025 Critical Patch Update* *Date: *23 January 2025 at 03:42:22 CET *To: *oss-security () lists openwall com *Reply-To: *oss-security () lists openwall com Hi, Once in a while, Oracle publishes what they call Critical Patch Update documents, which list many vulnerabilities addressed across many Oracle products, some of them Open Source and some not. This is great, but it would be even better if Oracle also communicated to oss-security about those vulnerabilities in its Open Source products, perhaps one message per product (e.g., MySQL separately from VirtualBox). I hope someone from Oracle reads this and will get the wheels moving. Anyone? Meanwhile, the latest Critical Patch Update is: https://blogs.oracle.com/security/post/january-2025-cpu-released https://www.oracle.com/security-alerts/cpujan2025.html For MySQL, it says: https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL "Oracle MySQL Risk Matrix This Critical Patch Update contains 39 new security patches, plus additional third party patches noted below, for Oracle MySQL. 4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here." and links to: https://www.oracle.com/security-alerts/cpujan2025verbose.html#MSQL and lists additional information on some CVEs not included in the matrix itself (duplicate or not vulnerable). With so many CVEs, all of this is rather long, but I imagine someone from Oracle - or someone external - could copy-paste the "English text form of this Risk Matrix" and the extra notes on a few CVEs to a separate message focusing on MySQL. Similarly, there's info on a couple of VirtualBox CVEs here, which would ideally be a separate message with copy-pasted detail: https://www.oracle.com/security-alerts/cpujan2025.html#AppendixOVIR https://www.oracle.com/security-alerts/cpujan2025verbose.html#OVIR Perhaps there's more Open Source software listed in there, which needs similar treatment. Not only this time, but each time, please. Alexander
Current thread:
- Oracle January 2025 Critical Patch Update Solar Designer (Jan 22)
- Re: Oracle January 2025 Critical Patch Update John Haxby (Jan 23)
- Message not available
- Re: [External] : Fwd: [oss-security] Oracle January 2025 Critical Patch Update Bruce Lowenthal (Jan 23)
- Re: [External] : Fwd: [oss-security] Oracle January 2025 Critical Patch Update Solar Designer (Jan 23)
- Re: Re: [External] : Fwd: [oss-security] Oracle January 2025 Critical Patch Update Douglas R. Reno (Jan 23)
- Re: Re: [External] : Fwd: [oss-security] Oracle January 2025 Critical Patch Update Solar Designer (Jan 24)
- Re: Re: [External] : Fwd: [oss-security] Oracle January 2025 Critical Patch Update Douglas R. Reno (Jan 25)
- Re: Re: [External] : Fwd: [oss-security] Oracle January 2025 Critical Patch Update Bruce Lowenthal (Jan 27)
- Re: [External] : Fwd: [oss-security] Oracle January 2025 Critical Patch Update Bruce Lowenthal (Jan 23)
- Re: [External] : Fwd: [oss-security] Oracle January 2025 Critical Patch Update Bruce Lowenthal (Jan 24)
- Re: Oracle January 2025 Critical Patch Update Solar Designer (Jan 23)
- Re: Oracle January 2025 Critical Patch Update Sam James (Jan 25)
- Re: Oracle January 2025 Critical Patch Update John Haxby (Jan 29)
