CVE-2006-2937

Summary

CVECVE-2006-2937
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2006-09-28 18:07:00 UTC
Updated2018-10-18 16:43:00 UTC
DescriptionOpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition.

Risk And Classification

Problem Types: CWE-399

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Openssl Openssl 0.9.7 All All All
Application Openssl Openssl 0.9.7a All All All
Application Openssl Openssl 0.9.7b All All All
Application Openssl Openssl 0.9.7c All All All
Application Openssl Openssl 0.9.7d All All All
Application Openssl Openssl 0.9.7e All All All
Application Openssl Openssl 0.9.7f All All All
Application Openssl Openssl 0.9.7g All All All
Application Openssl Openssl 0.9.7h All All All
Application Openssl Openssl 0.9.7i All All All
Application Openssl Openssl 0.9.7j All All All
Application Openssl Openssl 0.9.7k All All All
Application Openssl Openssl 0.9.8 All All All
Application Openssl Openssl 0.9.8a All All All
Application Openssl Openssl 0.9.8b All All All
Application Openssl Openssl 0.9.8c All All All
Application Openssl Openssl 0.9.7 All All All
Application Openssl Openssl 0.9.7a All All All
Application Openssl Openssl 0.9.7b All All All
Application Openssl Openssl 0.9.7c All All All
Application Openssl Openssl 0.9.7d All All All
Application Openssl Openssl 0.9.7e All All All
Application Openssl Openssl 0.9.7f All All All
Application Openssl Openssl 0.9.7g All All All
Application Openssl Openssl 0.9.7h All All All
Application Openssl Openssl 0.9.7i All All All
Application Openssl Openssl 0.9.7j All All All
Application Openssl Openssl 0.9.7k All All All
Application Openssl Openssl 0.9.8 All All All
Application Openssl Openssl 0.9.8a All All All
Application Openssl Openssl 0.9.8b All All All
Application Openssl Openssl 0.9.8c All All All

References

ReferenceSourceLinkTags
Kolab Server Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
SnapGear Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
IBM X-Force Exchange XF exchange.xforce.ibmcloud.com
Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Cisco Products OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
HP System Management Homepage Apache and OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
FreeBSD update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Red Hat update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
VMware Workstation 6 Release Notes CONFIRM www.vmware.com
OpenSSL Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
The Slackware Linux Project: Slackware Security Advisories SLACKWARE slackware.com Patch
Solaris OpenSSL Denial of Service Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
2006-0054 TRUSTIX www.trustix.org Patch
VMware ESX Server 2.5.3 Upgrade Patch 6 (for 2.5.3 Systems) CONFIRM www.vmware.com
SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Xerox ESS/ Network Controller OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
US-CERT Technical Cyber Security Alert TA06-333A -- Apple Releases Security Update to Address Multiple Vulnerabilities CERT www.us-cert.gov US Government Resource
VMware Player Release Notes CONFIRM www.vmware.com
SUSE updates for openssh, openssl, and bind9 - Advisories - Secunia SECUNIA secunia.com
Webmail - OVH VUPEN www.vupen.com
SecurityTracker.com Archives - OpenSSL ASN.1 Bugs, SSL_get_shared_ciphers() Buffer Overflow, and SSLv2 Client Error Lets Remote Users Denial of Service or Execute Arbitrary Code SECTRACK securitytracker.com Patch
US-CERT Vulnerability Note VU#247744 CERT-VN www.kb.cert.org Patch, US Government Resource
Support REDHAT www.redhat.com
Serv-U FTP Server OpenSSL Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
FreeBSD-SA-06:23.openssl FREEBSD security.freebsd.org Patch, Vendor Advisory
VMware ESX Server 2.1.3 Upgrade Patch 4 (for 2.1.3 Systems) CONFIRM www.vmware.com
SourceForge.net: SysAdmin Tools from ITeF!x: Files CONFIRM sourceforge.net
rhn.redhat.com | Red Hat Support REDHAT www.redhat.com Patch
Debian -- Security Information -- DSA-1185-2 openssl DEBIAN www.debian.org Patch
Webmail - OVH VUPEN www.vupen.com
VMSA-2008-0005.1 - VMware CONFIRM www.vmware.com
Download Patch ESX-9986131 for VMware ESX Server 3.0.1 CONFIRM www.vmware.com
VMWare ESX Server Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
VMware Server Release Notes CONFIRM www.vmware.com
NetBSD update for OpenSSL - Advisories - Secunia SECUNIA secunia.com
Sun Grid Engine Multiple OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Webmail - OVH VUPEN www.vupen.com
Webmail - OVH VUPEN www.vupen.com
[Security-announce] VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues MLIST lists.vmware.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Serv-U Release Notes - Current CONFIRM www.serv-u.com Patch
SUSE update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Webmail - OVH VUPEN www.vupen.com
Webmail - OVH VUPEN www.vupen.com
Security Announcement SUSE www.novell.com Patch, Vendor Advisory
Cisco - Networking, Cloud, and Cybersecurity Solutions CISCO www.cisco.com
HP Tru64 UNIX Multiple SSL and BIND Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
SecurityFocus BUGTRAQ www.securityfocus.com
APPLE-SA-2006-11-28 Security Update 2006-007 APPLE lists.apple.com
Repository / Oval Repository OVAL oval.cisecurity.org
SecurityFocus BUGTRAQ www.securityfocus.com
OpenBSD update for OpenSSL - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Webmail - OVH VUPEN www.vupen.com
VMware ESX Server 2.5.4 Upgrade Patch 3 (for 2.5.4 Systems Only) CONFIRM www.vmware.com
Mandriva update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
#102668: Security Vulnerabilities In OpenSSL Affect Sun Grid Engine 5.3 and N1 Grid Engine 6.0 SUNALERT sunsolve.sun.com Patch
rPath update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
'[security bulletin] HPSBOV02683 SSRT090208 rev.1 - HP Secure Web Server (SWS) for OpenVMS running Ap' - MARC HP marc.info
IT Resource Center - login / register HP itrc.hp.com
Advisories - Mandriva Linux MANDRIVA www.mandriva.com
20061001-01-P SGI patches.sgi.com
201534 SUNALERT sunsolve.sun.com
HPSBMA02250 SSRT061275 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Execution of Arbitrary Code and Denial of Service (DoS) - c01118771 - HP Business Support Center HP h20000.www2.hp.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
[#RPL-613] openssl vulnerabilities including remote unauthorized access: CVE-2006-2937 CVE-2006-2940 CVE-2006-3738 CVE-2006-4343 - rPath JIRA CONFIRM issues.rpath.com
usn/usn-353-1 - Ubuntu: Linux for human beings UBUNTU www.ubuntu.com Patch, Vendor Advisory
F-Secure Products OpenSSL ASN.1 Denial Of Service Vulnerability - Advisories - Secunia SECUNIA secunia.com
www.openssl.org/news/secadv_20060928.txt CONFIRM www.openssl.org Patch, Vendor Advisory
Security Announcement SUSE www.novell.com Patch, Vendor Advisory
www.arkoon.fr/upload/alertes/37AK-2006-06-FR-1.1_FAST360_OPENSSL_ASN1.pdf CONFIRM www.arkoon.fr Patch, Vendor Advisory
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Ubuntu update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Advisories - Mandriva Linux MANDRIVA www.mandriva.com
IBM HMC OpenSSH / OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
support.attachmate.com/techdocs/2374.html CONFIRM support.attachmate.com
Mandriva update for ntp - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
OpenPKG Corporation: Security: Security Advisories OPENPKG www.openpkg.org Patch, Vendor Advisory
Debian update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Cisco Security Response: Multiple Vulnerabilities in OpenSSL Library  [Cisco GSS 4400 Series Global Site Selector Appliances] - Cisco Systems CISCO www.cisco.com
OpenVPN 2.0.x Change Log CONFIRM openvpn.net Patch
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Webmail - OVH VUPEN www.vupen.com
www.arkoon.fr/upload/alertes/41AK-2006-08-FR-1.1_SSL360_OPENSSL_ASN1.pdf CONFIRM www.arkoon.fr
VMware Workstation 5.5 Release Notes CONFIRM www.vmware.com
Cisco Products OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
'Internet Systems Consortium Security Advisory. [revised]' - MARC MLIST marc.info
rPath update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
ASA-2006-260 HP-UX OpenSSL Denial of Service (DoS), Increase Privilige (HPSBUX02174) CONFIRM support.avaya.com
HP Insight Management Agents SSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Webmail - OVH VUPEN www.vupen.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
HP-UX update for OpenSSL - Advisories - Secunia SECUNIA secunia.com
About the security content of Security Update 2006-007 CONFIRM docs.info.apple.com
VMware ACE Release Notes CONFIRM www.vmware.com
VMware Player Release Notes CONFIRM www.vmware.com
[Full-disclosure] [SECURITY] OpenSSL 0.9.8d and 0.9.7l released FULLDISC lists.grok.org.uk Patch
F-Secure Security Bulletin FSC-2006-6 CONFIRM www.f-secure.com
cwRsync OpenSSL Vulnerabilities and OpenSSH Weakness - Advisories - Secunia SECUNIA secunia.com
Avaya PDS HP-UX Secure Shell / OpenSSL Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Trustix updates for openssh and openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Gentoo update for openssl - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Mandriva update for MySQL - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
OpenBSD 4.0 errata OPENBSD openbsd.org Patch
www.xerox.com/downloads/usa/en/c/cert_ESSNetwork_XRX07001_v1.pdf CONFIRM www.xerox.com
404 Not Found CONFIRM kolab.org Patch
Gentoo Linux Documentation -- OpenSSL: Multiple vulnerabilities GENTOO security.gentoo.org
Gentoo update for emul-linux-x86-baselibs - Advisories - Secunia SECUNIA secunia.com
29260 OSVDB www.osvdb.org
Gentoo Linux Documentation -- AMD64 x86 emulation base libraries: OpenSSL multiple vulnerabilities GENTOO www.gentoo.org
IT Resource Center - login / register HP itrc.hp.com
#102747: Security Vulnerabilities in OpenSSL May Lead to a Denial of Service (DoS) to Applications SUNALERT sunsolve.sun.com
Slackware update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
SSRT071304 HP www2.itrc.hp.com
SecurityFocus BUGTRAQ www.securityfocus.com
Advisories - Mandriva Linux MANDRIVA www.mandriva.com
Download Patch ESX-3069097 for VMware ESX Server 3.0.1 CONFIRM www.vmware.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
VMware Server 1.0.5 and Workstation 6.0.3 Multiple Vulnerabilities BID www.securityfocus.com
200585 SUNALERT sunsolve.sun.com
Red Hat Network Satellite Server Update for Solaris Client - Advisories - Community SECUNIA secunia.com
SecurityFocus BUGTRAQ www.securityfocus.com
BIND OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
FileZilla / FileZilla Server Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
HP-UX update for Apache - Advisories - Secunia SECUNIA secunia.com
Reflection for Secure IT Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com SECUNIA secunia.com
VMware ESX Server 2.0.2 Upgrade Patch 4 (for 2.0.2 Systems) CONFIRM www.vmware.com
ASA-2006-220 (RHSA-2006-0695) CONFIRM support.avaya.com Patch
OpenSSL ASN.1 Structures Denial of Service Vulnerability BID www.securityfocus.com Patch
NetBSD-SA2008-007 NETBSD ftp.netbsd.org
Webmail - OVH VUPEN www.vupen.com
Avaya Products OpenSSL Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Webmail - OVH VUPEN www.vupen.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

OrganizationPublishedContributorStatement
Red Hat2007-03-14Mark J CoxRed Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Legacy QID Mappings

  • 390284 Oracle Managed Virtualization (VM) Server for x86 Security Update for Open Secure Sockets Layer (OpenSSL) (OVMSA-2023-0013)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report