// For flags

CVE-2006-2940

openssl public key DoS

Severity Score

7.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra time to process when using RSA signature verification.

OpenSSL 0.9.7 en versiones anteriores a 0.9.7l, 0.9.8 en versiones anteriores a 0.9.8d y versiones anteriores permite a atacantes provocar una denegación de servicio (consumo de CPU) a través de claves públicas parasitarias con valores grandes de (1) "exponente público" o (2) "módulo público" en certificados X.509 que requiere tiempo extra de procesamiento cuando utiliza una verificación de firma RSA.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-06-09 CVE Reserved
  • 2006-09-28 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-18 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
CAPEC
References (144)
URL Tag Source
http://docs.info.apple.com/article.html?artnum=304829 X_refsource_confirm
http://issues.rpath.com/browse/RPL-613 X_refsource_confirm
http://kolab.org/security/kolab-vendor-notice-11.txt X_refsource_confirm
http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049715.html Mailing List
http://lists.vmware.com/pipermail/security-announce/2008/000008.html Mailing List
http://marc.info/?l=bind-announce&m=116253119512445&w=2 Mailing List
http://openvpn.net/changelog.html X_refsource_confirm
http://secunia.com/advisories/22298 Third Party Advisory
http://secunia.com/advisories/22487 Third Party Advisory
http://secunia.com/advisories/22626 Third Party Advisory
http://secunia.com/advisories/22671 Third Party Advisory
http://secunia.com/advisories/22758 Third Party Advisory
http://secunia.com/advisories/22772 Third Party Advisory
http://secunia.com/advisories/22799 Third Party Advisory
http://secunia.com/advisories/23038 Third Party Advisory
http://secunia.com/advisories/23155 Third Party Advisory
http://secunia.com/advisories/23280 Third Party Advisory
http://secunia.com/advisories/23309 Third Party Advisory
http://secunia.com/advisories/23340 Third Party Advisory
http://secunia.com/advisories/23351 Third Party Advisory
http://secunia.com/advisories/23680 Third Party Advisory
http://secunia.com/advisories/23794 Third Party Advisory
http://secunia.com/advisories/23915 Third Party Advisory
http://secunia.com/advisories/24930 Third Party Advisory
http://secunia.com/advisories/24950 Third Party Advisory
http://secunia.com/advisories/25889 Third Party Advisory
http://secunia.com/advisories/26329 Third Party Advisory
http://secunia.com/advisories/26893 Third Party Advisory
http://secunia.com/advisories/30124 Third Party Advisory
http://secunia.com/advisories/31492 Third Party Advisory
http://secunia.com/advisories/31531 Third Party Advisory
http://securitytracker.com/id?1016943 Vdb Entry
http://securitytracker.com/id?1017522 Vdb Entry
http://sourceforge.net/project/shownotes.php?release_id=461863&group_id=69227 X_refsource_confirm
http://support.attachmate.com/techdocs/2374.html X_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-220.htm X_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-260.htm X_refsource_confirm
http://www.arkoon.fr/upload/alertes/37AK-2006-06-FR-1.1_FAST360_OPENSSL_ASN1.pdf X_refsource_confirm
http://www.arkoon.fr/upload/alertes/41AK-2006-08-FR-1.1_SSL360_OPENSSL_ASN1.pdf X_refsource_confirm
http://www.openssl.org/news/secadv_20060928.txt X_refsource_confirm
http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html X_refsource_confirm
http://www.osvdb.org/29261 Vdb Entry
http://www.securityfocus.com/archive/1/447318/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/447393/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/456546/100/200/threaded Mailing List
http://www.securityfocus.com/archive/1/489739/100/0/threaded Mailing List
http://www.securityfocus.com/bid/20247 Vdb Entry
http://www.securityfocus.com/bid/22083 Vdb Entry
http://www.securityfocus.com/bid/28276 Vdb Entry
http://www.serv-u.com/releasenotes X_refsource_confirm
http://www.uniras.gov.uk/niscc/docs/re-20060928-00661.pdf?lang=en X_refsource_misc
http://www.us-cert.gov/cas/techalerts/TA06-333A.html Third Party Advisory
http://www.vmware.com/security/advisories/VMSA-2008-0005.html X_refsource_confirm
http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html X_refsource_confirm
http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html X_refsource_confirm
http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html X_refsource_confirm
http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html X_refsource_confirm
http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html X_refsource_confirm
http://www.vmware.com/support/player/doc/releasenotes_player.html X_refsource_confirm
http://www.vmware.com/support/player2/doc/releasenotes_player2.html X_refsource_confirm
http://www.vmware.com/support/server/doc/releasenotes_server.html X_refsource_confirm
http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html X_refsource_confirm
http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html X_refsource_confirm
http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html X_refsource_confirm
http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html X_refsource_confirm
http://www.vupen.com/english/advisories/2006/3820 Vdb Entry
http://www.vupen.com/english/advisories/2006/3860 Vdb Entry
http://www.vupen.com/english/advisories/2006/3869 Vdb Entry
http://www.vupen.com/english/advisories/2006/3902 Vdb Entry
http://www.vupen.com/english/advisories/2006/3936 Vdb Entry
http://www.vupen.com/english/advisories/2006/4019 Vdb Entry
http://www.vupen.com/english/advisories/2006/4036 Vdb Entry
http://www.vupen.com/english/advisories/2006/4264 Vdb Entry
http://www.vupen.com/english/advisories/2006/4327 Vdb Entry
http://www.vupen.com/english/advisories/2006/4329 Vdb Entry
http://www.vupen.com/english/advisories/2006/4401 Vdb Entry
http://www.vupen.com/english/advisories/2006/4417 Vdb Entry
http://www.vupen.com/english/advisories/2006/4750 Vdb Entry
http://www.vupen.com/english/advisories/2006/4980 Vdb Entry
http://www.vupen.com/english/advisories/2007/0343 Vdb Entry
http://www.vupen.com/english/advisories/2007/1401 Vdb Entry
http://www.vupen.com/english/advisories/2007/2315 Vdb Entry
http://www.vupen.com/english/advisories/2007/2783 Vdb Entry
http://www.vupen.com/english/advisories/2008/0905/references Vdb Entry
http://www.vupen.com/english/advisories/2008/2396 Vdb Entry
http://www.xerox.com/downloads/usa/en/c/cert_ESSNetwork_XRX07001_v1.pdf X_refsource_confirm
https://exchange.xforce.ibmcloud.com/vulnerabilities/29230 Vdb Entry
https://issues.rpath.com/browse/RPL-1633 X_refsource_confirm
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10311 Signature
URL Date SRC
URL Date SRC
URL Date SRC
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.asc 2018-10-18
ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc 2018-10-18
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771 2018-10-18
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100 2018-10-18
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540 2018-10-18
http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html 2018-10-18
http://marc.info/?l=bugtraq&m=130497311408250&w=2 2018-10-18
http://openbsd.org/errata.html#openssl2 2018-10-18
http://secunia.com/advisories/22094 2018-10-18
http://secunia.com/advisories/22116 2018-10-18
http://secunia.com/advisories/22130 2018-10-18
http://secunia.com/advisories/22165 2018-10-18
http://secunia.com/advisories/22166 2018-10-18
http://secunia.com/advisories/22172 2018-10-18
http://secunia.com/advisories/22186 2018-10-18
http://secunia.com/advisories/22193 2018-10-18
http://secunia.com/advisories/22207 2018-10-18
http://secunia.com/advisories/22212 2018-10-18
http://secunia.com/advisories/22216 2018-10-18
http://secunia.com/advisories/22220 2018-10-18
http://secunia.com/advisories/22240 2018-10-18
http://secunia.com/advisories/22259 2018-10-18
http://secunia.com/advisories/22260 2018-10-18
http://secunia.com/advisories/22284 2018-10-18
http://secunia.com/advisories/22330 2018-10-18
http://secunia.com/advisories/22385 2018-10-18
http://secunia.com/advisories/22460 2018-10-18
http://secunia.com/advisories/22500 2018-10-18
http://secunia.com/advisories/22544 2018-10-18
http://security.freebsd.org/advisories/FreeBSD-SA-06:23.openssl.asc 2018-10-18
http://security.gentoo.org/glsa/glsa-200610-11.xml 2018-10-18
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.676946 2018-10-18
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102668-1 2018-10-18
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102747-1 2018-10-18
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200585-1 2018-10-18
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201534-1 2018-10-18
http://www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_response09186a008077af1b.html 2018-10-18
http://www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtml 2018-10-18
http://www.debian.org/security/2006/dsa-1185 2018-10-18
http://www.debian.org/security/2006/dsa-1195 2018-10-18
http://www.gentoo.org/security/en/glsa/glsa-200612-11.xml 2018-10-18
http://www.mandriva.com/security/advisories?name=MDKSA-2006:172 2018-10-18
http://www.mandriva.com/security/advisories?name=MDKSA-2006:177 2018-10-18
http://www.mandriva.com/security/advisories?name=MDKSA-2006:178 2018-10-18
http://www.novell.com/linux/security/advisories/2006_24_sr.html 2018-10-18
http://www.novell.com/linux/security/advisories/2006_58_openssl.html 2018-10-18
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.021-openssl.html 2018-10-18
http://www.redhat.com/support/errata/RHSA-2006-0695.html 2018-10-18
http://www.redhat.com/support/errata/RHSA-2008-0629.html 2018-10-18
http://www.trustix.org/errata/2006/0054 2018-10-18
http://www.ubuntu.com/usn/usn-353-1 2018-10-18
http://www.ubuntu.com/usn/usn-353-2 2018-10-18
https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144 2018-10-18
https://access.redhat.com/security/cve/CVE-2006-2940 2008-08-13
https://bugzilla.redhat.com/show_bug.cgi?id=430654 2008-08-13
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.1c
Search vendor "Openssl" for product "Openssl" and version "0.9.1c"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.2b
Search vendor "Openssl" for product "Openssl" and version "0.9.2b"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.3
Search vendor "Openssl" for product "Openssl" and version "0.9.3"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.3a
Search vendor "Openssl" for product "Openssl" and version "0.9.3a"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.4
Search vendor "Openssl" for product "Openssl" and version "0.9.4"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.5
Search vendor "Openssl" for product "Openssl" and version "0.9.5"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.5
Search vendor "Openssl" for product "Openssl" and version "0.9.5"
beta1
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.5
Search vendor "Openssl" for product "Openssl" and version "0.9.5"
beta2
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.5a
Search vendor "Openssl" for product "Openssl" and version "0.9.5a"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.5a
Search vendor "Openssl" for product "Openssl" and version "0.9.5a"
beta1
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.5a
Search vendor "Openssl" for product "Openssl" and version "0.9.5a"
beta2
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6
Search vendor "Openssl" for product "Openssl" and version "0.9.6"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6
Search vendor "Openssl" for product "Openssl" and version "0.9.6"
beta1
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6
Search vendor "Openssl" for product "Openssl" and version "0.9.6"
beta2
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6
Search vendor "Openssl" for product "Openssl" and version "0.9.6"
beta3
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6a
Search vendor "Openssl" for product "Openssl" and version "0.9.6a"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6a
Search vendor "Openssl" for product "Openssl" and version "0.9.6a"
beta1
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6a
Search vendor "Openssl" for product "Openssl" and version "0.9.6a"
beta2
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6a
Search vendor "Openssl" for product "Openssl" and version "0.9.6a"
beta3
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6b
Search vendor "Openssl" for product "Openssl" and version "0.9.6b"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6c
Search vendor "Openssl" for product "Openssl" and version "0.9.6c"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6d
Search vendor "Openssl" for product "Openssl" and version "0.9.6d"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6e
Search vendor "Openssl" for product "Openssl" and version "0.9.6e"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6f
Search vendor "Openssl" for product "Openssl" and version "0.9.6f"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6g
Search vendor "Openssl" for product "Openssl" and version "0.9.6g"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6h
Search vendor "Openssl" for product "Openssl" and version "0.9.6h"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6i
Search vendor "Openssl" for product "Openssl" and version "0.9.6i"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6j
Search vendor "Openssl" for product "Openssl" and version "0.9.6j"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6k
Search vendor "Openssl" for product "Openssl" and version "0.9.6k"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6l
Search vendor "Openssl" for product "Openssl" and version "0.9.6l"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.6m
Search vendor "Openssl" for product "Openssl" and version "0.9.6m"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7
Search vendor "Openssl" for product "Openssl" and version "0.9.7"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7a
Search vendor "Openssl" for product "Openssl" and version "0.9.7a"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7b
Search vendor "Openssl" for product "Openssl" and version "0.9.7b"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7c
Search vendor "Openssl" for product "Openssl" and version "0.9.7c"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7d
Search vendor "Openssl" for product "Openssl" and version "0.9.7d"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7e
Search vendor "Openssl" for product "Openssl" and version "0.9.7e"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7f
Search vendor "Openssl" for product "Openssl" and version "0.9.7f"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7g
Search vendor "Openssl" for product "Openssl" and version "0.9.7g"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7h
Search vendor "Openssl" for product "Openssl" and version "0.9.7h"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7i
Search vendor "Openssl" for product "Openssl" and version "0.9.7i"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7j
Search vendor "Openssl" for product "Openssl" and version "0.9.7j"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.7k
Search vendor "Openssl" for product "Openssl" and version "0.9.7k"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.8
Search vendor "Openssl" for product "Openssl" and version "0.9.8"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.8a
Search vendor "Openssl" for product "Openssl" and version "0.9.8a"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.8b
Search vendor "Openssl" for product "Openssl" and version "0.9.8b"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
0.9.8c
Search vendor "Openssl" for product "Openssl" and version "0.9.8c"
-
Affected