CVE-2006-2940

Summary

CVECVE-2006-2940
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2006-09-28 18:07:00 UTC
Updated2018-10-18 16:44:00 UTC
DescriptionOpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra time to process when using RSA signature verification.

Risk And Classification

Problem Types: CWE-399

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Openssl Openssl 0.9.1c All All All
Application Openssl Openssl 0.9.2b All All All
Application Openssl Openssl 0.9.3 All All All
Application Openssl Openssl 0.9.3a All All All
Application Openssl Openssl 0.9.4 All All All
Application Openssl Openssl 0.9.5 All All All
Application Openssl Openssl 0.9.5 beta1 All All
Application Openssl Openssl 0.9.5 beta2 All All
Application Openssl Openssl 0.9.5a All All All
Application Openssl Openssl 0.9.5a beta1 All All
Application Openssl Openssl 0.9.5a beta2 All All
Application Openssl Openssl 0.9.6 All All All
Application Openssl Openssl 0.9.6 beta1 All All
Application Openssl Openssl 0.9.6 beta2 All All
Application Openssl Openssl 0.9.6 beta3 All All
Application Openssl Openssl 0.9.6a All All All
Application Openssl Openssl 0.9.6a beta1 All All
Application Openssl Openssl 0.9.6a beta2 All All
Application Openssl Openssl 0.9.6a beta3 All All
Application Openssl Openssl 0.9.6b All All All
Application Openssl Openssl 0.9.6c All All All
Application Openssl Openssl 0.9.6d All All All
Application Openssl Openssl 0.9.6e All All All
Application Openssl Openssl 0.9.6f All All All
Application Openssl Openssl 0.9.6g All All All
Application Openssl Openssl 0.9.6h All All All
Application Openssl Openssl 0.9.6i All All All
Application Openssl Openssl 0.9.6j All All All
Application Openssl Openssl 0.9.6k All All All
Application Openssl Openssl 0.9.6l All All All
Application Openssl Openssl 0.9.6m All All All
Application Openssl Openssl 0.9.7 All All All
Application Openssl Openssl 0.9.7a All All All
Application Openssl Openssl 0.9.7b All All All
Application Openssl Openssl 0.9.7c All All All
Application Openssl Openssl 0.9.7d All All All
Application Openssl Openssl 0.9.7e All All All
Application Openssl Openssl 0.9.7f All All All
Application Openssl Openssl 0.9.7g All All All
Application Openssl Openssl 0.9.7h All All All
Application Openssl Openssl 0.9.7i All All All
Application Openssl Openssl 0.9.7j All All All
Application Openssl Openssl 0.9.7k All All All
Application Openssl Openssl 0.9.8 All All All
Application Openssl Openssl 0.9.8a All All All
Application Openssl Openssl 0.9.8b All All All
Application Openssl Openssl 0.9.8c All All All
Application Openssl Openssl 0.9.1c All All All
Application Openssl Openssl 0.9.2b All All All
Application Openssl Openssl 0.9.3 All All All
Application Openssl Openssl 0.9.3a All All All
Application Openssl Openssl 0.9.4 All All All
Application Openssl Openssl 0.9.5 All All All
Application Openssl Openssl 0.9.5 beta1 All All
Application Openssl Openssl 0.9.5 beta2 All All
Application Openssl Openssl 0.9.5a All All All
Application Openssl Openssl 0.9.5a beta1 All All
Application Openssl Openssl 0.9.5a beta2 All All
Application Openssl Openssl 0.9.6 All All All
Application Openssl Openssl 0.9.6 beta1 All All
Application Openssl Openssl 0.9.6 beta2 All All
Application Openssl Openssl 0.9.6 beta3 All All
Application Openssl Openssl 0.9.6a All All All
Application Openssl Openssl 0.9.6a beta1 All All
Application Openssl Openssl 0.9.6a beta2 All All
Application Openssl Openssl 0.9.6a beta3 All All
Application Openssl Openssl 0.9.6b All All All
Application Openssl Openssl 0.9.6c All All All
Application Openssl Openssl 0.9.6d All All All
Application Openssl Openssl 0.9.6e All All All
Application Openssl Openssl 0.9.6f All All All
Application Openssl Openssl 0.9.6g All All All
Application Openssl Openssl 0.9.6h All All All
Application Openssl Openssl 0.9.6i All All All
Application Openssl Openssl 0.9.6j All All All
Application Openssl Openssl 0.9.6k All All All
Application Openssl Openssl 0.9.6l All All All
Application Openssl Openssl 0.9.6m All All All
Application Openssl Openssl 0.9.7 All All All
Application Openssl Openssl 0.9.7a All All All
Application Openssl Openssl 0.9.7b All All All
Application Openssl Openssl 0.9.7c All All All
Application Openssl Openssl 0.9.7d All All All
Application Openssl Openssl 0.9.7e All All All
Application Openssl Openssl 0.9.7f All All All
Application Openssl Openssl 0.9.7g All All All
Application Openssl Openssl 0.9.7h All All All
Application Openssl Openssl 0.9.7i All All All
Application Openssl Openssl 0.9.7j All All All
Application Openssl Openssl 0.9.7k All All All
Application Openssl Openssl 0.9.8 All All All
Application Openssl Openssl 0.9.8a All All All
Application Openssl Openssl 0.9.8b All All All
Application Openssl Openssl 0.9.8c All All All

References

ReferenceSourceLinkTags
Kolab Server Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
SnapGear Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Cisco Products OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
HP System Management Homepage Apache and OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
FreeBSD update for openssl - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Red Hat update for openssl - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
VMware Workstation 6 Release Notes CONFIRM www.vmware.com
OpenSSL Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
The Slackware Linux Project: Slackware Security Advisories SLACKWARE slackware.com
Solaris OpenSSL Denial of Service Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Debian update for openssl096 - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
2006-0054 TRUSTIX www.trustix.org
VMware ESX Server 2.5.3 Upgrade Patch 6 (for 2.5.3 Systems) CONFIRM www.vmware.com
SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia SECUNIA secunia.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Xerox ESS/ Network Controller OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
US-CERT Technical Cyber Security Alert TA06-333A -- Apple Releases Security Update to Address Multiple Vulnerabilities CERT www.us-cert.gov US Government Resource
VMware Player Release Notes CONFIRM www.vmware.com
SUSE updates for openssh, openssl, and bind9 - Advisories - Secunia SECUNIA secunia.com
SecurityTracker.com Archives - OpenSSL ASN.1 Bugs, SSL_get_shared_ciphers() Buffer Overflow, and SSLv2 Client Error Lets Remote Users Denial of Service or Execute Arbitrary Code SECTRACK securitytracker.com
Support REDHAT www.redhat.com
Serv-U FTP Server OpenSSL Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
FreeBSD-SA-06:23.openssl FREEBSD security.freebsd.org
VMware ESX Server 2.1.3 Upgrade Patch 4 (for 2.1.3 Systems) CONFIRM www.vmware.com
SourceForge.net: SysAdmin Tools from ITeF!x: Files CONFIRM sourceforge.net
rPath update for openssl - Advisories - Secunia SECUNIA secunia.com
rhn.redhat.com | Red Hat Support REDHAT www.redhat.com Vendor Advisory
Oracle Products Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Debian -- Security Information -- DSA-1185-2 openssl DEBIAN www.debian.org
Webmail - OVH VUPEN www.vupen.com
VMSA-2008-0005.1 - VMware CONFIRM www.vmware.com
OpenSSL Public Key Processing Denial of Service Vulnerability BID www.securityfocus.com
Download Patch ESX-9986131 for VMware ESX Server 3.0.1 CONFIRM www.vmware.com
usn/usn-353-2 - Ubuntu: Linux for human beings UBUNTU www.ubuntu.com
VMWare ESX Server Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
VMware Server Release Notes CONFIRM www.vmware.com
NetBSD update for OpenSSL - Advisories - Secunia SECUNIA secunia.com
Sun Grid Engine Multiple OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Webmail - OVH VUPEN www.vupen.com
Webmail - OVH VUPEN www.vupen.com
[Security-announce] VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues MLIST lists.vmware.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Serv-U Release Notes - Current CONFIRM www.serv-u.com
issues.rpath.com/browse/RPL-1633 CONFIRM issues.rpath.com
SUSE update for openssl - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Webmail - OVH VUPEN www.vupen.com
Webmail - OVH VUPEN www.vupen.com
Security Announcement SUSE www.novell.com
Cisco - Networking, Cloud, and Cybersecurity Solutions CISCO www.cisco.com
HP Tru64 UNIX Multiple SSL and BIND Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
SecurityFocus BUGTRAQ www.securityfocus.com
APPLE-SA-2006-11-28 Security Update 2006-007 APPLE lists.apple.com
SecurityFocus BUGTRAQ www.securityfocus.com
OpenBSD update for OpenSSL - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Webmail - OVH VUPEN www.vupen.com
Oracle Critical Patch Update - January 2007 CONFIRM www.oracle.com
VMware ESX Server 2.5.4 Upgrade Patch 3 (for 2.5.4 Systems Only) CONFIRM www.vmware.com
29261 OSVDB www.osvdb.org
Mandriva update for openssl - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
#102668: Security Vulnerabilities In OpenSSL Affect Sun Grid Engine 5.3 and N1 Grid Engine 6.0 SUNALERT sunsolve.sun.com
SecurityTracker.com Archives - Oracle Database and Other Products Have 52 Unspecified Vulnerabilities With Unspecified Impact SECTRACK securitytracker.com
rPath update for openssl - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
'[security bulletin] HPSBOV02683 SSRT090208 rev.1 - HP Secure Web Server (SWS) for OpenVMS running Ap' - MARC HP marc.info
IT Resource Center - login / register HP itrc.hp.com
Advisories - Mandriva Linux MANDRIVA www.mandriva.com
20061001-01-P SGI patches.sgi.com
201534 SUNALERT sunsolve.sun.com
HPSBMA02250 SSRT061275 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Execution of Arbitrary Code and Denial of Service (DoS) - c01118771 - HP Business Support Center HP h20000.www2.hp.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
[#RPL-613] openssl vulnerabilities including remote unauthorized access: CVE-2006-2937 CVE-2006-2940 CVE-2006-3738 CVE-2006-4343 - rPath JIRA CONFIRM issues.rpath.com
usn/usn-353-1 - Ubuntu: Linux for human beings UBUNTU www.ubuntu.com
www.openssl.org/news/secadv_20060928.txt CONFIRM www.openssl.org
Security Announcement SUSE www.novell.com
www.arkoon.fr/upload/alertes/37AK-2006-06-FR-1.1_FAST360_OPENSSL_ASN1.pdf CONFIRM www.arkoon.fr
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Ubuntu update for openssl - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
www.uniras.gov.uk/niscc/docs/re-20060928-00661.pdf MISC www.uniras.gov.uk
Advisories - Mandriva Linux MANDRIVA www.mandriva.com
Repository / Oval Repository OVAL oval.cisecurity.org
IBM HMC OpenSSH / OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
support.attachmate.com/techdocs/2374.html CONFIRM support.attachmate.com
Mandriva update for ntp - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
OpenPKG Corporation: Security: Security Advisories OPENPKG www.openpkg.org
Debian update for openssl - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Cisco Security Response: Multiple Vulnerabilities in OpenSSL Library  [Cisco GSS 4400 Series Global Site Selector Appliances] - Cisco Systems CISCO www.cisco.com
OpenVPN 2.0.x Change Log CONFIRM openvpn.net
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Webmail - OVH VUPEN www.vupen.com
www.arkoon.fr/upload/alertes/41AK-2006-08-FR-1.1_SSL360_OPENSSL_ASN1.pdf CONFIRM www.arkoon.fr
VMware Workstation 5.5 Release Notes CONFIRM www.vmware.com
Cisco Products OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
'Internet Systems Consortium Security Advisory. [revised]' - MARC MLIST marc.info
rPath update for openssl - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
ASA-2006-260 HP-UX OpenSSL Denial of Service (DoS), Increase Privilige (HPSBUX02174) CONFIRM support.avaya.com
HP Insight Management Agents SSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Webmail - OVH VUPEN www.vupen.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
HP-UX update for OpenSSL - Advisories - Secunia SECUNIA secunia.com
About the security content of Security Update 2006-007 CONFIRM docs.info.apple.com
VMware ACE Release Notes CONFIRM www.vmware.com
Debian -- Security Information -- DSA-1195-1 openssl096 DEBIAN www.debian.org
VMware Player Release Notes CONFIRM www.vmware.com
[Full-disclosure] [SECURITY] OpenSSL 0.9.8d and 0.9.7l released FULLDISC lists.grok.org.uk
cwRsync OpenSSL Vulnerabilities and OpenSSH Weakness - Advisories - Secunia SECUNIA secunia.com
Avaya PDS HP-UX Secure Shell / OpenSSL Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Trustix updates for openssh and openssl - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Gentoo update for openssl - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Mandriva update for MySQL - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
OpenBSD 4.0 errata OPENBSD openbsd.org
www.xerox.com/downloads/usa/en/c/cert_ESSNetwork_XRX07001_v1.pdf CONFIRM www.xerox.com
404 Not Found CONFIRM kolab.org
Gentoo Linux Documentation -- OpenSSL: Multiple vulnerabilities GENTOO security.gentoo.org
Gentoo update for emul-linux-x86-baselibs - Advisories - Secunia SECUNIA secunia.com
Gentoo Linux Documentation -- AMD64 x86 emulation base libraries: OpenSSL multiple vulnerabilities GENTOO www.gentoo.org
IT Resource Center - login / register HP itrc.hp.com
IBM X-Force Exchange XF exchange.xforce.ibmcloud.com
#102747: Security Vulnerabilities in OpenSSL May Lead to a Denial of Service (DoS) to Applications SUNALERT sunsolve.sun.com
Slackware update for openssl - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
SSRT071304 HP www2.itrc.hp.com
SecurityFocus BUGTRAQ www.securityfocus.com
Advisories - Mandriva Linux MANDRIVA www.mandriva.com
Download Patch ESX-3069097 for VMware ESX Server 3.0.1 CONFIRM www.vmware.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
VMware Server 1.0.5 and Workstation 6.0.3 Multiple Vulnerabilities BID www.securityfocus.com
200585 SUNALERT sunsolve.sun.com
Red Hat Network Satellite Server Update for Solaris Client - Advisories - Community SECUNIA secunia.com
SecurityFocus BUGTRAQ www.securityfocus.com
BIND OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Oracle January 2007 Security Update Multiple Vulnerabilities BID www.securityfocus.com
FileZilla / FileZilla Server Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
HP-UX update for Apache - Advisories - Secunia SECUNIA secunia.com
Reflection for Secure IT Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com SECUNIA secunia.com
VMware ESX Server 2.0.2 Upgrade Patch 4 (for 2.0.2 Systems) CONFIRM www.vmware.com
ASA-2006-220 (RHSA-2006-0695) CONFIRM support.avaya.com
NetBSD-SA2008-007 NETBSD ftp.netbsd.org
Webmail - OVH VUPEN www.vupen.com
Avaya Products OpenSSL Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Webmail - OVH VUPEN www.vupen.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

OrganizationPublishedContributorStatement
Red Hat2007-03-14Mark J CoxRed Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Legacy QID Mappings

  • 390284 Oracle Managed Virtualization (VM) Server for x86 Security Update for Open Secure Sockets Layer (OpenSSL) (OVMSA-2023-0013)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report