Other CryptoAPI Applications vunerable to IE SSL vunerability ?

From: Christoph Kaminski (chriz@gmx.net)
Date: 08/12/02


From: "Christoph Kaminski" <chriz@gmx.net>
Date: Mon, 12 Aug 2002 16:27:48 +0200


Are other applications relying on the CryptoAPI eg. IIS and Active Directory
to the same IIS SSL vunerability described here:

http://online.securityfocus.com/archive/1/286895/2002-08-09/2002-08-15/1

?
Are client certificates vunerable, too (making all smart card authentication
insecure) ?

chriz.