oss-sec mailing list archives

Re: Re: CVE's for SSLv2 support


From: Tim <tim-security () sentinelchicken org>
Date: Tue, 1 Mar 2016 11:31:44 -0800



For example, there might be a crypto library intended for
communication on isolated networks to high-value embedded devices that
support only SSLv2, and cannot and will not ever be updated.

Just because there is no easy fix for a vulnerability, does that mean
it isn't a vulnerability?

tim


Current thread: