PT-2006-1067 · Openssl+2 · Openssl+2

Mark Jcox

·

Publicado

2006-09-28

·

Atualizado

2024-06-15

·

CVE-2006-2940

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: OpenSSL versions 0.9.7 through 0.9.7l OpenSSL versions 0.9.8 through 0.9.8d OpenSSL versions prior to 0.9.8d
Description: The issue allows attackers to cause a denial of service via parasitic public keys with large public exponent or public modulus values in X.509 certificates. This requires extra time to process when using RSA signature verification. Multiple vulnerabilities in the OpenSSL package can lead to violations of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely, potentially allowing an attacker to cause a denial of service or gain access to encrypted data without knowing the encryption key.
Recommendations: For OpenSSL versions 0.9.7 through 0.9.7l, update to version 0.9.7l or later. For OpenSSL versions 0.9.8 through 0.9.8d, update to version 0.9.8d or later. For all versions prior to 0.9.8d, update to version 0.9.8d or later. As a temporary workaround, consider restricting the use of RSA signature verification with X.509 certificates to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09525
BDU:2015-09905
CVE-2006-2940
DSA-1185-2
DSA-1195-1
HPSBUX02174
OPENSUSE-SU-2024:11125-1
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
RHSA-2006:0695
RHSA-2006_0695
RHSA-2008:0264
RHSA-2008:0525
RHSA-2008:0629
SUSE-FU-2022:0445-1

Produtos afetados

Hp-Ux
Openssl
Red Hat