Is it just me or did Oracle release over 100 patches in their latest critical patch update (CPU, good thing they chose an acronym not used for anything else in computing). They claim that some vulnerabilities affect multiple products and their 'risk matricies' list the vulnerability for each product, which I assume would also need to be patched for each product.
They can't seem to get it right. They either release too few patches, ineffective patches, no patches or now, too many patches. Then again Pete Finnigan who knows his Oracle seems happy enough, so maybe I am missing something.
Oracle is following its usual 'partial disclosure' policy. Although several of the vulns are being researched and fully disclosed at
Good luck testing that sucker.
Barry Irwin

Schneier on Security: Friday Squid Blogging: Preserving Giant Squid
0 Trackbacks