CVE-2006-2937: High severity openssl openssl vulnerability
Published Sep 28, 2006
·Updated
OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition.
Affected Software
16 affected components
OpenSSL OpenSSL=0.9.8b
OpenSSL OpenSSL=0.9.8c
OpenSSL OpenSSL=0.9.7c
OpenSSL OpenSSL=0.9.7j
OpenSSL OpenSSL=0.9.7k
OpenSSL OpenSSL=0.9.7g
OpenSSL OpenSSL=0.9.7d
OpenSSL OpenSSL=0.9.7
OpenSSL OpenSSL=0.9.7e
OpenSSL OpenSSL=0.9.7b
OpenSSL OpenSSL=0.9.8a
OpenSSL OpenSSL=0.9.7i
OpenSSL OpenSSL=0.9.7h
OpenSSL OpenSSL=0.9.8
OpenSSL OpenSSL=0.9.7a
OpenSSL OpenSSL=0.9.7f
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Sep 28, 2006
CVE Published
06:07 PM
Data Sourced
via NVD·06:07 PM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2937?
CVE-2006-2937 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
2
Which versions of OpenSSL are affected by CVE-2006-2937?
OpenSSL versions before 0.9.7l and 0.9.8d are affected by CVE-2006-2937.
3
How do I fix CVE-2006-2937?
To fix CVE-2006-2937, upgrade to OpenSSL version 0.9.7l or 0.9.8d or later.
4
What type of attack does CVE-2006-2937 enable?
CVE-2006-2937 allows remote attackers to cause a denial of service through malformed ASN.1 structures.
5
What is affected by the denial of service in CVE-2006-2937?
The denial of service in CVE-2006-2937 affects the memory consumption and performance of the OpenSSL libcrypto library.