Solved

Ghost Vulnerability - Statement of Impact on a Windows Environment

Posted on 2015-02-20
2
146 Views
Last Modified: 2015-03-05
Hi Guys

I have to produce a statement of impact for the Ghost Vulnerability in Windows Environment (no linux).

I realise this is primarily a Linux issue, but i am struggling to find any formal references to confirm how Windows is affected (..or not).

Also, is there any impact on the networking peripherals such as firewalls and Internet facing F5 load-balancers?

Could anyone please point me at some reputable reference resources?

Thanks


M
0
Comment
Question by:mk112233
2 Comments
 
LVL 25

Accepted Solution

by:
Zephyr ICT earned 500 total points
ID: 40620898
I think you need to look at it more from an application point of view regarding Windows vulnerability <> Ghost.
For example, what applications are running on Windows that might be vulnerable and check out the statements the vendors made regarding Ghost and their applications. Thinking about Cisco or Juniper software clients for network protection or maybe VPN software clients...

Here is the Cisco page regarding their devices/software and this vulnerability

Here is a page I found listing some major vendors and the links to their report regarding the vulnerability, you'll see F5 is listed along with some other major vendors.

As far as I can tell there is no official Microsoft bulletin regarding CVE-2015-0235, might be I missed it though.
0
 
LVL 11

Expert Comment

by:andreas
ID: 40621355
Windows SHOULD not be affected in its core. But installed software might bring some components of glibc, may be even statical linked so its not easy to see. this could then pose the same risks as on linux ,even remote code execution.

Windows itself should not contain any glibc code, else microsoft should mention the lgpl licensed code somewhere.

for the network envoronment it depends on the operating system running on it. if it has a vulnerable glibc it might be vunerable like linux systems.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now