SearchSecurity.com has a good news story about CPU July 2005
The article starts by saying how many bugs have been fixed and also the fact that many outstanding security bugs have not been fixed and a second concern that at least one fix from the last patch didn’t work. Then there are some quotes from me and then from David Litchfield and finally from Cesar Cerrudo who recommends that the patch sets should not be installed on a production server until they have been tested for a few months. I am not sure I would go this far. Installing the patches even if some fixes do not work as announced as seen in the last couple of weeks for the last patch set is surely better than not installing at all. The patch sets will fix more than they miss. Although I can see Cesars point of view that if even one bug fix does not work properly then the patch is essentially useless. It is all down to Q&A as Cesar says.
Read Shawna's article, it’s very good. I also updated my Pete Finnigan in the news page.