PT-2006-1068 · Openssl+2 · Openssl+2

Dr. S. N. Henson

·

Publicado

2006-09-28

·

Atualizado

2024-06-15

·

CVE-2006-2937

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: OpenSSL versions 0.9.7 through 0.9.7l OpenSSL versions 0.9.8 through 0.9.8d
Description: The issue is related to an error in processing malformed ASN.1 structures, which may lead to an infinite loop and consumption of memory, resulting in a denial of service. This can be triggered remotely, potentially affecting the availability of the service. Multiple vulnerabilities in the OpenSSL package may also lead to violations of confidentiality, integrity, and availability of protected information.
Recommendations: For OpenSSL versions 0.9.7 through 0.9.7l, update to version 0.9.7l or later. For OpenSSL versions 0.9.8 through 0.9.8d, update to version 0.9.8d or later. As a temporary workaround, consider restricting access to the service to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09525
CVE-2006-2937
DSA-1185-2
HPSBUX02174
OPENSUSE-SU-2024:11125-1
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
RHSA-2006:0695
RHSA-2006_0695
RHSA-2008:0264
RHSA-2008:0525
RHSA-2008:0629
SUSE-FU-2022:0445-1

Produtos afetados

Hp-Ux
Openssl
Red Hat