Advisory – ‘DROWN’ (Cross-protocol attack on TLS using SSLv2) vulnerability

‘DROWN’ – Decrypting RSA with Obsolete and Weakened eNcryption Various products may be affected by this vulnerability, given the common vulnerability and exposures designation of CVE-2016-0800. A cross-protocol attack was discovered that could lead to decryption of TLS sessions by using a server supporting SSLv2 and EXPORT cipher suites. Traffic… Continue reading

Advisory – ‘Skeleton’ glibc Vulnerability

‘Skeleton’ Buffer Overflow Vulnerability Various products may be affected by this vulnerability, given the common vulnerability and exposures designation of CVE-2015_7547. Multiple vulnerabilities in the ‘libresolv’ library of the ‘GNU C Library’ (aka ‘glibc’), could allow a remote attacker to remotely execute code. This typically affects systems based on Linux… Continue reading

Advisory – MS Windows kernel vulnerability

Various security vulnerabilities in various MS Windows OS’s (Client and Server) Various remote code execution vulnerability have been identified, and given the common vulnerability and exposures designation of CVE-2015-1719 to CVE-2015-1727. We have seen recent activity on customers’ Windows servers, relating to new exploits that are currently active. The exploits… Continue reading