PT-2006-1067 · Openssl+2 · Openssl+2

Mark Jcox

·

Published

2006-09-28

·

Updated

2024-06-15

·

CVE-2006-2940

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: OpenSSL versions 0.9.7 through 0.9.7l OpenSSL versions 0.9.8 through 0.9.8d OpenSSL versions prior to 0.9.8d
Description: The issue allows attackers to cause a denial of service via parasitic public keys with large public exponent or public modulus values in X.509 certificates. This requires extra time to process when using RSA signature verification. Multiple vulnerabilities in the OpenSSL package can lead to violations of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely, potentially allowing an attacker to cause a denial of service or gain access to encrypted data without knowing the encryption key.
Recommendations: For OpenSSL versions 0.9.7 through 0.9.7l, update to version 0.9.7l or later. For OpenSSL versions 0.9.8 through 0.9.8d, update to version 0.9.8d or later. For all versions prior to 0.9.8d, update to version 0.9.8d or later. As a temporary workaround, consider restricting the use of RSA signature verification with X.509 certificates to minimize the risk of exploitation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09525
BDU:2015-09905
CVE-2006-2940
DSA-1185-2
DSA-1195-1
HPSBUX02174
OPENSUSE-SU-2024:11125-1
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
RHSA-2006:0695
RHSA-2006_0695
RHSA-2008:0264
RHSA-2008:0525
RHSA-2008:0629
SUSE-FU-2022:0445-1

Affected Products

Hp-Ux
Openssl
Red Hat