Mapping between CVE numbers and Solaris patches for October 2010 CPU
By chandan on Oct 01, 2010
Hi, this is Eric Maurice.
In a previous blog entry, we invited customers to provide feedback in regards to the content of the Critical Patch Update advisory for Oracle Sun products. Such feedback is very valuable, and continues to drive the definition of Oracle Software Security Assurance policies.
As a result of the feedback received, Oracle has updated its policies to include the mapping of each vulnerability's CVE number to the particular Solaris package patch version (patchid), in all future Solaris CPU Patch Availability Documents. The updated policy will be effective with the October 2010 Critical Patch Update onward.
With the Critical Patch Update, Oracle's objective is to positively influence the security posture of all customers by providing the most effective vulnerability remediation program in the industry. This means not only producing effective, fully tested, security patches on all supported platform and version combinations every quarter, but also providing sufficient information about the newly-fixed vulnerabilities to enable customers to make proper patching decision and effectively manage their security management costs.
For More Information:
- The Critical Patch Updates and Security Alerts page is located at http://www.oracle.com/technology/deploy/security/alerts.htm
- A short document describing the changes in security policies for the Sun product lines is available at http://www.oracle.com/technetwork/topics/security/changesforsunsecuritypolicies-162219.html
- More information about Oracle Software Security Assurance is available on http://www.oracle.com/us/support/assurance/index.html