CVE-2006-3127: High severity Sun Java Enterprise System vulnerability
Memory leak in Network Security Services (NSS) 3.11, as used in Sun Java Enterprise System 2003Q4 through 2005Q1 and Java System Directory Server 5.2, allows remote attackers to cause a denial of service (memory consumption) by performing a large number of RSA cryptographic operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3127?
CVE-2006-3127 is classified as a moderate severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2006-3127?
To mitigate CVE-2006-3127, upgrade to a fixed version of Network Security Services that addresses the memory leak issue.
What systems are affected by CVE-2006-3127?
CVE-2006-3127 affects Sun Java Enterprise System versions 2003Q4 through 2005Q1 and Sun Java System Directory Server version 5.2.
What type of attack does CVE-2006-3127 enable?
CVE-2006-3127 enables attackers to cause a denial of service by consuming memory through repeated RSA operations.
Is there a workaround for CVE-2006-3127?
While upgrading is recommended, limiting the number of RSA operations from untrusted sources may serve as a temporary workaround for CVE-2006-3127.