Solved

Ghost Vulnerability - Statement of Impact on a Windows Environment

Posted on 2015-02-20
2
152 Views
Last Modified: 2015-03-05
Hi Guys

I have to produce a statement of impact for the Ghost Vulnerability in Windows Environment (no linux).

I realise this is primarily a Linux issue, but i am struggling to find any formal references to confirm how Windows is affected (..or not).

Also, is there any impact on the networking peripherals such as firewalls and Internet facing F5 load-balancers?

Could anyone please point me at some reputable reference resources?

Thanks


M
0
Comment
Question by:mk112233
2 Comments
 
LVL 25

Accepted Solution

by:
Zephyr ICT earned 500 total points
ID: 40620898
I think you need to look at it more from an application point of view regarding Windows vulnerability <> Ghost.
For example, what applications are running on Windows that might be vulnerable and check out the statements the vendors made regarding Ghost and their applications. Thinking about Cisco or Juniper software clients for network protection or maybe VPN software clients...

Here is the Cisco page regarding their devices/software and this vulnerability

Here is a page I found listing some major vendors and the links to their report regarding the vulnerability, you'll see F5 is listed along with some other major vendors.

As far as I can tell there is no official Microsoft bulletin regarding CVE-2015-0235, might be I missed it though.
0
 
LVL 11

Expert Comment

by:andreas
ID: 40621355
Windows SHOULD not be affected in its core. But installed software might bring some components of glibc, may be even statical linked so its not easy to see. this could then pose the same risks as on linux ,even remote code execution.

Windows itself should not contain any glibc code, else microsoft should mention the lgpl licensed code somewhere.

for the network envoronment it depends on the operating system running on it. if it has a vulnerable glibc it might be vunerable like linux systems.
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this increasingly digital world, security hacks are no longer just a threat, but a reality. As we've witnessed with Target's big identity hack 2013, Heartbleed in 2015, and now Cloudbleed, companies and their leaders need to prepare for the unthi…
As cyber crime continues to grow in both numbers and sophistication, a troubling trend of optimization has emerged over the last year.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question