Security News > 2020 > January > Yo, sysadmins! Thought Patch Tuesday was big? Oracle says 'hold my Java' with huge 334 security flaw fix bundle

Oracle has released a sweeping set of security patches across the breadth of its software line.
The January update, delivered one day after Microsoft, Intel, Adobe, and others dropped their scheduled monthly patches, addresses a total of 334 security vulnerabilities across 93 different products from the enterprise giant.
Three of those are remotely exploitable without authorization, including one flaw in Apache Tomcat, one in Big Red's database gateway, and one for the Core RDBMS product.
Also of note was CVE-2020-2696, an elevation of privilege flaw in the Solaris 10 Common Desktop Environment, which was discovered by Marco Ivaldi, principal security adviser at Italian infosec shop Mediaservice.net.
In a detailed dissection of the bug, Ivaldi describes the flaw as a "Cute straight-out-of-the-manual memory corruption" issue, and suggested a number of similar bugs are likely to exist.
News URL
https://go.theregister.co.uk/feed/www.theregister.co.uk/2020/01/15/oracle_january_patches/
Related news
- Patch Tuesday: January 2025 Security Update Patches Exploited Elevation of Privilege Attacks (source)
- January 2025 Patch Tuesday forecast: Changes coming in cybersecurity guidance (source)
- Week in review: Exploited Ivanti Connect Secure zero-day, Patch Tuesday forecast (source)
- Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws (source)
- Windows Patch Tuesday hits snag with Citrix software, workarounds published (source)
- 7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now (source)
- Oracle Releases January 2025 Patch to Address 318 Flaws Across Major Products (source)
- Asus lets processor security fix slip out early, AMD confirms patch in progress (source)
- February 2025 Patch Tuesday forecast: New directions for AI development (source)
- Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-15 | CVE-2020-2696 | Unspecified vulnerability in Oracle Solaris 10 Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). | 8.8 |