CVE-2006-2940

Scores

EPSS

0.166very_low16.6%
0%20%40%60%80%100%

Percentile: 16.6%

CVSS

7.8high2.0
0246810

CVSS Score: 7.8/10

All CVSS Scores

CVSS 2.0
7.8

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Description

OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) “public exponent” or (2) “public modulus” values in X.509 certificates that require extra time to process when using RSA signature verification.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhat

CWEs

CWE-399

Related Vulnerabilities

Vulnerable Software (19)

Type: Configuration

Product: openssl

Operating System: rhel 2.1

Trait:
{  "fixed": "0.9.6b-46"}

Source: redhat

Type: Configuration

Product: openssl

Operating System: rhel 3

Trait:
{  "fixed": "0.9.7a-33.21"}

Source: redhat

Type: Configuration

Product: openssl

Operating System: rhel 4

Trait:
{  "fixed": "0.9.7a-43.14"}

Source: redhat

Type: Configuration

Product: openssl

Operating System: debian

Trait:
{  "fixed": "0.9.8c-2"}

Source: debian

Type: Configuration

Product: openssl095a

Operating System: rhel 2.1

Trait:
{  "fixed": "0.9.5a-32"}

Source: redhat

Type: Configuration

Product: openssl096

Operating System: rhel 2.1

Trait:
{  "fixed": "0.9.6-32"}

Source: redhat

Type: Configuration

Product: openssl096

Operating System: debian

Trait:
{  "unfixed": true}

Source: debian

Type: Configuration

Product: openssl096b

Operating System: rhel 3

Trait:
{  "fixed": "0.9.6b-16.46"}

Source: redhat

Type: Configuration

Product: openssl096b

Operating System: rhel 4

Trait:
{  "fixed": "0.9.6b-22.46"}

Source: redhat

Type: Configuration

Product: openssl097

Operating System: debian

Trait:
{  "fixed": "0.9.7k-2"}

Source: debian