CVE-2006-2937

Scores

EPSS

0.075very_low7.5%
0%20%40%60%80%100%

Percentile: 7.5%

CVSS

7.8high2.0
0246810

CVSS Score: 7.8/10

All CVSS Scores

CVSS 2.0
7.8

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Description

OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhat

CWEs

CWE-399

Related Vulnerabilities

Recommendations

Source: nvd

See the systems affected section of this document for information about specific vendors. Users who compile OpenSSL from source are encouraged to apply the updates listed in OpenSSL Security Advisory 20060928.

URL: http://www.kb.cert.org/vuls/id/247744

Vulnerable Software (19)

Type: Configuration

Product: openssl

Operating System: rhel 2.1

Trait:
{  "fixed": "0.9.6b-46"}

Source: redhat

Type: Configuration

Product: openssl

Operating System: rhel 3

Trait:
{  "fixed": "0.9.7a-33.21"}

Source: redhat

Type: Configuration

Product: openssl

Operating System: rhel 4

Trait:
{  "fixed": "0.9.7a-43.14"}

Source: redhat

Type: Configuration

Product: openssl

Operating System: debian

Trait:
{  "fixed": "0.9.8c-2"}

Source: debian

Type: Configuration

Product: openssl095a

Operating System: rhel 2.1

Trait:
{  "fixed": "0.9.5a-32"}

Source: redhat

Type: Configuration

Product: openssl096

Operating System: rhel 2.1

Trait:
{  "fixed": "0.9.6-32"}

Source: redhat

Type: Configuration

Product: openssl096

Operating System: debian

Trait:
{  "unaffected": true}

Source: debian

Type: Configuration

Product: openssl096b

Operating System: rhel 3

Trait:
{  "fixed": "0.9.6b-16.46"}

Source: redhat

Type: Configuration

Product: openssl096b

Operating System: rhel 4

Trait:
{  "fixed": "0.9.6b-22.46"}

Source: redhat

Type: Configuration

Product: openssl097

Operating System: debian

Trait:
{  "fixed": "0.9.7k-2"}

Source: debian