DROWN vulnerability in cryptographic protocols

March 1, 2016

New vulnerability related to SSL and TLS was released. Vulnerable are web servers, SMTP servers, IMAP and POP servers, and any other services that supports SSL/TLS. DROWN can be executed in case that service supports both SSLv2 and TLS or it shares its private key with any other service that support SSLv2. Technical paper that describes the vulnerability is available here. There is also possibility to test your website here.