Question

CVE-2014-6321 (also known as MS14-066) is a heap overflow vulnerability discovered by Microsoft engineers in Schannel,...

CVE-2014-6321 (also known as MS14-066) is a heap overflow vulnerability discovered by Microsoft engineers in Schannel, the SSL/TLS implementation used by Windows.

My Java application uses SSL (JSSE Implementation) and so now I'm wondering if my application is at risk due to this vulnerability or it is irrelevant?

0 0
Add a comment Improve this question Transcribed image text
Answer #1

The vulnerability (still undisclosed) is also described as "Microsoft Schannel Remote Code Execution Vulnerability", which indicates that it is an implementation weakness (namely, a probably boring buffer overflow), not a protocol weakness. Thus, there is no reason to believe that the vulnerability would be shared with any other independent implementation of the protocol.

(Furthermore, Java's implementation of SSL/TLS is not only independently developed; it is also written in Java, which is inherently resilient to buffer overflows, since all array accesses in Java are inherently validated against the actual array length.)

Add a comment
Know the answer?
Add Answer to:
CVE-2014-6321 (also known as MS14-066) is a heap overflow vulnerability discovered by Microsoft engineers in Schannel,...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around...

    Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT