Re: CVE-2013-4353 and CVSS v2 vector with Authentication set to None

2014-01-28 Thread Amarendra Godbole
Sorry folks - I was fixated on something else to see the obvious. -Amarendra On Sun, Jan 26, 2014 at 10:22 AM, Amarendra Godbole amarendra.godb...@gmail.com wrote: Hi, I am analyzing CVE-2013-4353, and the CVSS vector mentions Au parameter to N [1] From what I understand, the culprit code is

CVE-2013-4353 and CVSS v2 vector with Authentication set to None

2014-01-27 Thread Amarendra Godbole
Hi, I am analyzing CVE-2013-4353, and the CVSS vector mentions Au parameter to N [1] From what I understand, the culprit code is called in the Server Finish message of the handshake, which is the last step - by this time the client has authenticated the server (step 3). So why does the CVSS

CVE-2013-4353 and CVSS v2 vector with Authentication set to None

2014-01-26 Thread Amarendra Godbole
Hi, I am analyzing CVE-2013-4353, and the CVSS vector mentions Au parameter to N [1] From what I understand, the culprit code is called in the Server Finish message of the handshake, which is the last step - by this time the client has authenticated the server (step 3). So why does the CVSS