// For flags

CVE-2006-2937

openssl ASN.1 DoS

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition.

OpenSSL 0.9.7 en versiones anteriores a 0.9.7l y 0.9.8 en versiones anteriores a 0.9.8d permite a atacantes remotos provocar una denegación de servicio (bucle infinito y consumo de memoria) a través de estructuras ASN.1 mal formadas que desencadenan una condición de error manejada incorrectamente.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-06-09 CVE Reserved
  • 2006-09-28 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
CAPEC
References (138)
URL Tag Source
http://docs.info.apple.com/article.html?artnum=304829 X_refsource_confirm
http://issues.rpath.com/browse/RPL-613 X_refsource_confirm
http://lists.vmware.com/pipermail/security-announce/2008/000008.html Mailing List
http://marc.info/?l=bind-announce&m=116253119512445&w=2 Mailing List
http://secunia.com/advisories/22298 Third Party Advisory
http://secunia.com/advisories/22758 Third Party Advisory
http://secunia.com/advisories/22772 Third Party Advisory
http://secunia.com/advisories/22799 Third Party Advisory
http://secunia.com/advisories/23038 Third Party Advisory
http://secunia.com/advisories/23131 Third Party Advisory
http://secunia.com/advisories/23155 Third Party Advisory
http://secunia.com/advisories/23280 Third Party Advisory
http://secunia.com/advisories/23309 Third Party Advisory
http://secunia.com/advisories/23340 Third Party Advisory
http://secunia.com/advisories/23351 Third Party Advisory
http://secunia.com/advisories/23680 Third Party Advisory
http://secunia.com/advisories/23915 Third Party Advisory
http://secunia.com/advisories/24930 Third Party Advisory
http://secunia.com/advisories/24950 Third Party Advisory
http://secunia.com/advisories/25889 Third Party Advisory
http://secunia.com/advisories/26329 Third Party Advisory
http://secunia.com/advisories/30124 Third Party Advisory
http://secunia.com/advisories/31492 Third Party Advisory
http://secunia.com/advisories/31531 Third Party Advisory
http://sourceforge.net/project/shownotes.php?release_id=461863&group_id=69227 X_refsource_confirm
http://support.attachmate.com/techdocs/2374.html X_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-260.htm X_refsource_confirm
http://www.arkoon.fr/upload/alertes/41AK-2006-08-FR-1.1_SSL360_OPENSSL_ASN1.pdf X_refsource_confirm
http://www.f-secure.com/security/fsc-2006-6.shtml X_refsource_confirm
http://www.osvdb.org/29260 Vdb Entry
http://www.securityfocus.com/archive/1/447318/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/447393/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/456546/100/200/threaded Mailing List
http://www.securityfocus.com/archive/1/489739/100/0/threaded Mailing List
http://www.securityfocus.com/bid/28276 Vdb Entry
http://www.us-cert.gov/cas/techalerts/TA06-333A.html Third Party Advisory
http://www.vmware.com/security/advisories/VMSA-2008-0005.html X_refsource_confirm
http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html X_refsource_confirm
http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html X_refsource_confirm
http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html X_refsource_confirm
http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html X_refsource_confirm
http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html X_refsource_confirm
http://www.vmware.com/support/player/doc/releasenotes_player.html X_refsource_confirm
http://www.vmware.com/support/player2/doc/releasenotes_player2.html X_refsource_confirm
http://www.vmware.com/support/server/doc/releasenotes_server.html X_refsource_confirm
http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html X_refsource_confirm
http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html X_refsource_confirm
http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html X_refsource_confirm
http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html X_refsource_confirm
http://www.vupen.com/english/advisories/2006/3820 Vdb Entry
http://www.vupen.com/english/advisories/2006/3860 Vdb Entry
http://www.vupen.com/english/advisories/2006/3869 Vdb Entry
http://www.vupen.com/english/advisories/2006/3902 Vdb Entry
http://www.vupen.com/english/advisories/2006/3936 Vdb Entry
http://www.vupen.com/english/advisories/2006/4019 Vdb Entry
http://www.vupen.com/english/advisories/2006/4036 Vdb Entry
http://www.vupen.com/english/advisories/2006/4264 Vdb Entry
http://www.vupen.com/english/advisories/2006/4327 Vdb Entry
http://www.vupen.com/english/advisories/2006/4329 Vdb Entry
http://www.vupen.com/english/advisories/2006/4401 Vdb Entry
http://www.vupen.com/english/advisories/2006/4417 Vdb Entry
http://www.vupen.com/english/advisories/2006/4750 Vdb Entry
http://www.vupen.com/english/advisories/2006/4761 Vdb Entry
http://www.vupen.com/english/advisories/2006/4980 Vdb Entry
http://www.vupen.com/english/advisories/2007/0343 Vdb Entry
http://www.vupen.com/english/advisories/2007/1401 Vdb Entry
http://www.vupen.com/english/advisories/2007/2315 Vdb Entry
http://www.vupen.com/english/advisories/2007/2783 Vdb Entry
http://www.vupen.com/english/advisories/2008/0905/references Vdb Entry
http://www.vupen.com/english/advisories/2008/2396 Vdb Entry
http://www.xerox.com/downloads/usa/en/c/cert_ESSNetwork_XRX07001_v1.pdf X_refsource_confirm
https://exchange.xforce.ibmcloud.com/vulnerabilities/29228 Vdb Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10560 Signature
URL Date SRC
URL Date SRC
http://kolab.org/security/kolab-vendor-notice-11.txt 2018-10-18
http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049715.html 2018-10-18
http://openbsd.org/errata.html#openssl2 2018-10-18
http://openvpn.net/changelog.html 2018-10-18
http://secunia.com/advisories/22094 2018-10-18
http://secunia.com/advisories/22116 2018-10-18
http://secunia.com/advisories/22130 2018-10-18
http://secunia.com/advisories/22165 2018-10-18
http://secunia.com/advisories/22166 2018-10-18
http://secunia.com/advisories/22172 2018-10-18
http://secunia.com/advisories/22186 2018-10-18
http://secunia.com/advisories/22193 2018-10-18
http://secunia.com/advisories/22207 2018-10-18
http://secunia.com/advisories/22212 2018-10-18
http://secunia.com/advisories/22216 2018-10-18
http://secunia.com/advisories/22220 2018-10-18
http://secunia.com/advisories/22240 2018-10-18
http://secunia.com/advisories/22259 2018-10-18
http://secunia.com/advisories/22260 2018-10-18
http://secunia.com/advisories/22284 2018-10-18
http://secunia.com/advisories/22330 2018-10-18
http://security.freebsd.org/advisories/FreeBSD-SA-06:23.openssl.asc 2018-10-18
http://securitytracker.com/id?1016943 2018-10-18
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.676946 2018-10-18
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102668-1 2018-10-18
http://support.avaya.com/elmodocs2/security/ASA-2006-220.htm 2018-10-18
http://www.arkoon.fr/upload/alertes/37AK-2006-06-FR-1.1_FAST360_OPENSSL_ASN1.pdf 2018-10-18
http://www.debian.org/security/2006/dsa-1185 2018-10-18
http://www.kb.cert.org/vuls/id/247744 2018-10-18
http://www.novell.com/linux/security/advisories/2006_24_sr.html 2018-10-18
http://www.novell.com/linux/security/advisories/2006_58_openssl.html 2018-10-18
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.021-openssl.html 2018-10-18
http://www.openssl.org/news/secadv_20060928.txt 2018-10-18
http://www.redhat.com/support/errata/RHSA-2006-0695.html 2018-10-18
http://www.securityfocus.com/bid/20248 2018-10-18
http://www.serv-u.com/releasenotes 2018-10-18
http://www.trustix.org/errata/2006/0054 2018-10-18
http://www.ubuntu.com/usn/usn-353-1 2018-10-18
URL Date SRC
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.asc 2018-10-18
ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc 2018-10-18
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771 2018-10-18
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100 2018-10-18
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540 2018-10-18
http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html 2018-10-18
http://marc.info/?l=bugtraq&m=130497311408250&w=2 2018-10-18
http://secunia.com/advisories/22385 2018-10-18
http://secunia.com/advisories/22460 2018-10-18
http://secunia.com/advisories/22487 2018-10-18
http://secunia.com/advisories/22544 2018-10-18
http://secunia.com/advisories/22626 2018-10-18
http://secunia.com/advisories/22671 2018-10-18
http://security.gentoo.org/glsa/glsa-200610-11.xml 2018-10-18
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102747-1 2018-10-18
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200585-1 2018-10-18
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201534-1 2018-10-18
http://www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_response09186a008077af1b.html 2018-10-18
http://www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtml 2018-10-18
http://www.gentoo.org/security/en/glsa/glsa-200612-11.xml 2018-10-18
http://www.mandriva.com/security/advisories?name=MDKSA-2006:172 2018-10-18
http://www.mandriva.com/security/advisories?name=MDKSA-2006:177 2018-10-18
http://www.mandriva.com/security/advisories?name=MDKSA-2006:178 2018-10-18
http://www.redhat.com/support/errata/RHSA-2008-0629.html 2018-10-18
https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144 2018-10-18
https://access.redhat.com/security/cve/CVE-2006-2937 2008-08-13
https://bugzilla.redhat.com/show_bug.cgi?id=430655 2008-08-13
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7
Search vendor "Openssl" for product "Openssl" and version "0.9.7"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7a
Search vendor "Openssl" for product "Openssl" and version "0.9.7a"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7b
Search vendor "Openssl" for product "Openssl" and version "0.9.7b"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7c
Search vendor "Openssl" for product "Openssl" and version "0.9.7c"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7d
Search vendor "Openssl" for product "Openssl" and version "0.9.7d"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7e
Search vendor "Openssl" for product "Openssl" and version "0.9.7e"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7f
Search vendor "Openssl" for product "Openssl" and version "0.9.7f"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7g
Search vendor "Openssl" for product "Openssl" and version "0.9.7g"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7h
Search vendor "Openssl" for product "Openssl" and version "0.9.7h"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7i
Search vendor "Openssl" for product "Openssl" and version "0.9.7i"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7j
Search vendor "Openssl" for product "Openssl" and version "0.9.7j"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7k
Search vendor "Openssl" for product "Openssl" and version "0.9.7k"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.8
Search vendor "Openssl" for product "Openssl" and version "0.9.8"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.8a
Search vendor "Openssl" for product "Openssl" and version "0.9.8a"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.8b
Search vendor "Openssl" for product "Openssl" and version "0.9.8b"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.8c
Search vendor "Openssl" for product "Openssl" and version "0.9.8c"
-
Affected