Factors Mitigating Browser issues

Server certificate validation vulnerability:

•        The vulnerability only affects how certificates from web servers are validated. It does not affect how code-signing certificates
or any other type of certificate are validated.

•        The specific checks that might be bypassed vary with both the user and the actions he may have taken during the current browsing session. An attacker could not predict with any degree of certainty which checks might be bypassed in a particular case.

•        The vulnerability does not provide any way to force users to the attacker's web site. It is likely that this vulnerability could only
be exploited in conjunction with a successful DNS poisoning or similar attack.

 

What did you think of this article?




Trackbacks
  • No trackbacks exist for this entry.
Comments
  • No comments exist for this entry.
Leave a comment

Submitted comments will be subject to moderation before being displayed.

 Enter the above security code (required)

 Name

 Email (will not be published)

 Website

Your comment is 0 characters limited to 3000 characters.