Skip to main content

how do I install a patch like 147904-04.zip?

Please note these java.net forums are being decommissioned and use the new and improved forums at https://community.oracle.com/community/java.
3 replies [Last post]
snmdla
Offline
Joined: 2012-03-06

Dear community,

I'm quite irritated: through the "Critical Patch Update July 2012
Patch Availability Document for Oracle Sun Products [ID 1446033.1]" we
got to know about "CVE-2011-4358", and, regarding Oracle GlassFish
Server 3.1.x, found the download

https://updates.oracle.com/all_unsigned/147904-04.zip

This download contains the file ogs-3.1.2-2-repo-linux-i386.zip, and
147904-06.html, giving the following "Patch Installation
Instructions":

"Unzip the downloaded ZIP file and follow the installation
instructions at
http://download.oracle.com/docs/cd/E18930_01/html/821-2427/index.html"

Now my problem is that the last given URL is the plain "Oracle
GlassFish Server 3.1 Installation Guide", and this does not contain
any instructions about how to deal with the files contained in
147904-04.zip!

Can you offer help, please?

Regards, Tom

Reply viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
oversteer
Offline
Joined: 2011-03-28

What files are in the zip file? I can't access it.

snmdla
Offline
Joined: 2012-03-06

README.147904-06
ogs-3.1.2-2-repo-linux-i386.zip
147904-06.html
LEGAL_LICENSE.TXT

The file ogs-3.1.2-2-repo-linux-i386.zip has numerous files in it:

host:/dir # unzip -l ogs-3.1.2-2-repo-linux-i386.zip
Archive: ogs-3.1.2-2-repo-linux-i386.zip
Length Date Time Name
-------- ---- ---- ----
0 07-12-12 07:46 linux-i386/
0 07-12-12 16:58 linux-i386/catalog/
72 07-12-12 16:58 linux-i386/catalog/attrs
5831 07-12-12 16:58 linux-i386/catalog/catalog
0 12-07-11 22:18 linux-i386/file/
0 07-12-12 08:13 linux-i386/file/00/
0 12-07-11 22:17 linux-i386/file/00/011b12/
2646 12-07-11 22:17 linux-i386/file/00/011b12/00011b12c1c35a78ec7b30685be85858c4e63732
0 12-07-11 22:17 linux-i386/file/00/1d2a15/
...
1044 07-12-12 08:14 linux-i386/pkg/glassfish-toplink-grid/3.1.2.2%2C0-5%3A20120711T195303Z
0 07-12-12 16:58 linux-i386/pkg/glassfish-scripting/
535 07-12-12 16:58 linux-i386/pkg/glassfish-scripting/3.1%2C0-41%3A20110208T202810Z
0 07-12-12 16:58 linux-i386/trans/
0 07-12-12 16:58 linux-i386/updatelog/
675 12-07-11 22:18 linux-i386/updatelog/2011120713
8119 07-12-12 08:14 linux-i386/updatelog/2012071123
82 07-12-12 16:58 linux-i386/updatelog/2012071207
567 12-07-11 22:16 linux-i386/cfg_cache
-------- -------
130392708 7329 files
host:/dir #

snmdla
Offline
Joined: 2012-03-06

I forked this issue to Oracle support, and they say "CVEs are not provided for the open source release of Glassfish."

So I fear, that, working with the open source release of Glassfish, we have no option than doing a new install with a newer release?