CVE-2006-3738: Buffer Overflow
Published Sep 28, 2006
·Updated
Buffer overflow in the SSLgetsharedciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.
Affected Software
16 affected components
OpenSSL OpenSSL=0.9.7
OpenSSL OpenSSL=0.9.7a
OpenSSL OpenSSL=0.9.7b
OpenSSL OpenSSL=0.9.7c
OpenSSL OpenSSL=0.9.7d
OpenSSL OpenSSL=0.9.7e
OpenSSL OpenSSL=0.9.7f
OpenSSL OpenSSL=0.9.7g
OpenSSL OpenSSL=0.9.7h
OpenSSL OpenSSL=0.9.7i
OpenSSL OpenSSL=0.9.7j
OpenSSL OpenSSL=0.9.7k
OpenSSL OpenSSL=0.9.8
OpenSSL OpenSSL=0.9.8a
OpenSSL OpenSSL=0.9.8b
OpenSSL OpenSSL=0.9.8c
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Sep 28, 2006
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:07 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-3738?
CVE-2006-3738 is classified as a high severity vulnerability due to the potential for remote code execution based on a buffer overflow.
2
How do I fix CVE-2006-3738?
To fix CVE-2006-3738, upgrade OpenSSL to version 0.9.7l or later, or 0.9.8d or later.
3
What software versions are affected by CVE-2006-3738?
CVE-2006-3738 affects OpenSSL versions earlier than 0.9.7l and 0.9.8d.
4
What impact does CVE-2006-3738 have on systems?
CVE-2006-3738 can lead to denial of service or remote execution of arbitrary code.
5
Are there any workarounds for CVE-2006-3738?
The recommended workaround for CVE-2006-3738 is to disable the use of shared ciphers if upgrading is not immediately feasible.