April 2008 CPU
Paul Wright April 15th, 2008
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2008.html
April 2008 CPU came out at 9.00pm UK time tonight as normal. Two of the vulnerabilities are ones that I found whilst working at NGS and are both PL/SQL injections but the most critical bug is the JInitiator JVM bug… Java Vulnerabilities are the subject of a Presentation I am giving next week at SANS Orlando http://www.sans.org/sans2008/night.php ..More to come on this subject.
Cheers,
Paul