Internet Security Systems (ISS), the security firm that provide products and services to protect against Internet threats, have discovered a vulnerability in the Netscape Network Security Services (NSS) library suite for Secure Sockets Layer (SSL) communication.
The vulnerability could result in remote compromise of products.
Netscape Enterprise Server and Sun One are widely used commercial web server platforms which make use of the NSS library. There is a security flaw in the NSS library that can result in arbitrary code execution on vulnerable systems during SSLv2 connection negotiation.
Full story... Source : ITVibe