[Full-Disclosure] SSL Vulnerability??

From: JV (jessevalentin_at_yahoo.com)
Date: 08/27/04

  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: [Full-Disclosure] Automated ssh scanning"
    To: full-disclosure@lists.netsys.com
    Date: Thu, 26 Aug 2004 16:16:33 -0700 (PDT)
    
    

    Here’s an interesting link having to do with a vulnerability found in the Netscape NSS library which will impact any “products making use of the library for SSL communication”. Might be possible to remotely compromise any sites affected by this issue.

     

    This has the potential to be very ugly since any site using SSL is usually trying to protect something valuable… banking, health information, etc..

     

    Some products making use of this library suite are:

    Netscape - Enterprise Server (NES) - All known versions

    Netscape - Personalization Engine (NPE) - All known versions

    Netscape - Directory Server (NDS) - All known versions

    Netscape - Certificate Management Server (CMS) - All known versions

    Sun - Sun One/iPlanet - All known versions

    Any application or product that integrates the NSS library suite and

    which implements SSLv2 ciphers

     

     

    Check out this link for more info and vendor supplied patches, etc.
    http://xforce.iss.net/xforce/alerts/id/180
     
    - Jesse

                    
    ---------------------------------
    Do you Yahoo!?
    Yahoo! Mail - 50x more storage than other providers!

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: [Full-Disclosure] Automated ssh scanning"
  • Quantcast