Schannel and TLS 1.x padding vulnerability (CVE-2014-8730)


hi all,

is implementation of tls microsoft secure channel (schannel) (http://msdn.microsoft.com/en-us/library/windows/desktop/aa380123%28v=vs.85%29.aspx) affected "cve-2014-8730 tls 1.x padding vulnerability"?

please see following links more details vulnerability:

  • http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-8730
  • https://community.qualys.com/blogs/securitylabs/2014/12/08/poodle-bites-tls


there confirmation microsoft schannel not affected vulnerability?

regards,
sanjay



no, microsoft schannell not affected.only f5 products affected: http://www.securityfocus.com/bid/71549

vadims podāns, aka powershell cryptoguy
weblog: en-us.sysadmins.lv
powershell pki module: pspki.codeplex.com
powershell cmdlet editor pscmdlethelpeditor.codeplex.com
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.



Windows Server  >  Security



Comments

Popular posts from this blog

Motherboard replacement

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state

Remote Desktop App - Error 0x207 or 0x607