Jul 27, 2016

Correspondance of CVE-2016-4438/s2-027



Do you know that ASM signatures supports CVE-2016-4438/S2-037?


I didnot confirm that in release notes and in DB(mysql) of ASM.




  • i assume you are wondering if the ASM protects against this vulnerability?


    as you already saw yourself there is nothing in the latest attack signature update about this, so i would say no, not at the moment.


    i can't find any specific information about it either to be able to determine if creating custom signature is possible. it at all possible you should restrict access to this component from untrusted networks.