CVE-2006-3738

Summary

CVECVE-2006-3738
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2006-09-28 18:07:00 UTC
Updated2018-10-17 21:29:00 UTC
DescriptionBuffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.

Risk And Classification

Problem Types: CWE-119

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Openssl Openssl 0.9.7 All All All
Application Openssl Openssl 0.9.7a All All All
Application Openssl Openssl 0.9.7b All All All
Application Openssl Openssl 0.9.7c All All All
Application Openssl Openssl 0.9.7d All All All
Application Openssl Openssl 0.9.7e All All All
Application Openssl Openssl 0.9.7f All All All
Application Openssl Openssl 0.9.7g All All All
Application Openssl Openssl 0.9.7h All All All
Application Openssl Openssl 0.9.7i All All All
Application Openssl Openssl 0.9.7j All All All
Application Openssl Openssl 0.9.7k All All All
Application Openssl Openssl 0.9.8 All All All
Application Openssl Openssl 0.9.8a All All All
Application Openssl Openssl 0.9.8b All All All
Application Openssl Openssl 0.9.8c All All All
Application Openssl Openssl 0.9.7 All All All
Application Openssl Openssl 0.9.7a All All All
Application Openssl Openssl 0.9.7b All All All
Application Openssl Openssl 0.9.7c All All All
Application Openssl Openssl 0.9.7d All All All
Application Openssl Openssl 0.9.7e All All All
Application Openssl Openssl 0.9.7f All All All
Application Openssl Openssl 0.9.7g All All All
Application Openssl Openssl 0.9.7h All All All
Application Openssl Openssl 0.9.7i All All All
Application Openssl Openssl 0.9.7j All All All
Application Openssl Openssl 0.9.7k All All All
Application Openssl Openssl 0.9.8 All All All
Application Openssl Openssl 0.9.8a All All All
Application Openssl Openssl 0.9.8b All All All
Application Openssl Openssl 0.9.8c All All All

References

ReferenceSourceLinkTags
Repository / Oval Repository OVAL oval.cisecurity.org
Kolab Server Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
SnapGear Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Cisco Products OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
HP System Management Homepage Apache and OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
FreeBSD update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Red Hat update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
OpenSSL Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
The Slackware Linux Project: Slackware Security Advisories SLACKWARE slackware.com Patch
Debian update for openssl096 - Advisories - Secunia SECUNIA secunia.com
2006-0054 TRUSTIX www.trustix.org Patch
VMware ESX Server 2.5.3 Upgrade Patch 6 (for 2.5.3 Systems) CONFIRM www.vmware.com
OpenSSL SSL_Get_Shared_Ciphers Buffer Overflow Vulnerability BID www.securityfocus.com Patch
SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia SECUNIA secunia.com
Xerox ESS/ Network Controller OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
US-CERT Technical Cyber Security Alert TA06-333A -- Apple Releases Security Update to Address Multiple Vulnerabilities CERT www.us-cert.gov US Government Resource
SUSE updates for openssh, openssl, and bind9 - Advisories - Secunia SECUNIA secunia.com
SecurityTracker.com Archives - OpenSSL ASN.1 Bugs, SSL_get_shared_ciphers() Buffer Overflow, and SSLv2 Client Error Lets Remote Users Denial of Service or Execute Arbitrary Code SECTRACK securitytracker.com Patch
Support REDHAT www.redhat.com
Serv-U FTP Server OpenSSL Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Webmail - OVH VUPEN www.vupen.com
VMware ESX Server 2.1.3 Upgrade Patch 4 (for 2.1.3 Systems) CONFIRM www.vmware.com
SourceForge.net: SysAdmin Tools from ITeF!x: Files CONFIRM sourceforge.net
rhn.redhat.com | Red Hat Support REDHAT www.redhat.com Patch
Oracle Products Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Debian -- Security Information -- DSA-1185-2 openssl DEBIAN www.debian.org Patch
Webmail - OVH VUPEN www.vupen.com
Download Patch ESX-9986131 for VMware ESX Server 3.0.1 CONFIRM www.vmware.com
VMWare ESX Server Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
NetBSD update for OpenSSL - Advisories - Secunia SECUNIA secunia.com
Sun Grid Engine Multiple OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Webmail - OVH VUPEN www.vupen.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Serv-U Release Notes - Current CONFIRM www.serv-u.com
SUSE update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Security Announcement SUSE www.novell.com Patch, Vendor Advisory
Cisco - Networking, Cloud, and Cybersecurity Solutions CISCO www.cisco.com
HP Tru64 UNIX Multiple SSL and BIND Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
SecurityFocus BUGTRAQ www.securityfocus.com
APPLE-SA-2006-11-28 Security Update 2006-007 APPLE lists.apple.com
SecurityFocus BUGTRAQ www.securityfocus.com
OpenBSD update for OpenSSL - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Webmail - OVH VUPEN www.vupen.com
Oracle Critical Patch Update - January 2007 CONFIRM www.oracle.com
VMware ESX Server 2.5.4 Upgrade Patch 3 (for 2.5.4 Systems Only) CONFIRM www.vmware.com
FreeBSD-SA-06:23 FREEBSD security.freebsd.org Patch, Vendor Advisory
Mandriva update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
#102668: Security Vulnerabilities In OpenSSL Affect Sun Grid Engine 5.3 and N1 Grid Engine 6.0 SUNALERT sunsolve.sun.com Patch
SecurityTracker.com Archives - Oracle Database and Other Products Have 52 Unspecified Vulnerabilities With Unspecified Impact SECTRACK securitytracker.com
rPath update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
'[security bulletin] HPSBOV02683 SSRT090208 rev.1 - HP Secure Web Server (SWS) for OpenVMS running Ap' - MARC HP marc.info
Repository / Oval Repository OVAL oval.cisecurity.org
IT Resource Center - login / register HP itrc.hp.com
Advisories - Mandriva Linux MANDRIVA www.mandriva.com
20061001-01-P SGI patches.sgi.com
HPSBMA02250 SSRT061275 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Execution of Arbitrary Code and Denial of Service (DoS) - c01118771 - HP Business Support Center HP h20000.www2.hp.com
Linux Terminal Server Project: Multiple vulnerabilities — Gentoo Linux Documentation GENTOO www.gentoo.org
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
[#RPL-613] openssl vulnerabilities including remote unauthorized access: CVE-2006-2937 CVE-2006-2940 CVE-2006-3738 CVE-2006-4343 - rPath JIRA CONFIRM issues.rpath.com
usn/usn-353-1 - Ubuntu: Linux for human beings UBUNTU www.ubuntu.com Patch
www.openssl.org/news/secadv_20060928.txt CONFIRM www.openssl.org
Security Announcement SUSE www.novell.com Patch, Vendor Advisory
US-CERT Vulnerability Note VU#547300 CERT-VN www.kb.cert.org US Government Resource
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Ubuntu update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Advisories - Mandriva Linux MANDRIVA www.mandriva.com
IBM HMC OpenSSH / OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Mandriva update for ntp - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
OpenPKG Corporation: Security: Security Advisories OPENPKG www.openpkg.org Patch, Vendor Advisory
Debian update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Cisco Security Response: Multiple Vulnerabilities in OpenSSL Library  [Cisco GSS 4400 Series Global Site Selector Appliances] - Cisco Systems CISCO www.cisco.com
OpenVPN 2.0.x Change Log CONFIRM openvpn.net Patch
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Nortel Communication Server OpenSSL Vulnerability - Advisories - Secunia SECUNIA secunia.com
Webmail - OVH VUPEN www.vupen.com
SecurityFocus BUGTRAQ www.securityfocus.com
Cisco Products OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
rPath update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
ASA-2006-260 HP-UX OpenSSL Denial of Service (DoS), Increase Privilige (HPSBUX02174) CONFIRM support.avaya.com
HP Insight Management Agents SSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Nortel Products OpenSSL Vulnerability - Advisories - Secunia SECUNIA secunia.com
Webmail - OVH VUPEN www.vupen.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
29262 OSVDB www.osvdb.org Patch
HP-UX update for OpenSSL - Advisories - Secunia SECUNIA secunia.com
About the security content of Security Update 2006-007 CONFIRM docs.info.apple.com
Debian -- Security Information -- DSA-1195-1 openssl096 DEBIAN www.debian.org Patch, Vendor Advisory
[Full-disclosure] [SECURITY] OpenSSL 0.9.8d and 0.9.7l released FULLDISC lists.grok.org.uk Patch
cwRsync OpenSSL Vulnerabilities and OpenSSH Weakness - Advisories - Secunia SECUNIA secunia.com
Avaya PDS HP-UX Secure Shell / OpenSSL Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
#102711: Security Vulnerabilities in OpenSSL May Lead to a Denial of Service (DoS) to Applications or Execution of Arbitrary Code With Elevated Privileges SUNALERT sunsolve.sun.com
Trustix updates for openssh and openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
Gentoo update for openssl - Advisories - Secunia SECUNIA secunia.com
Mandriva update for MySQL - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
OpenBSD 4.0 errata OPENBSD openbsd.org Patch
www.xerox.com/downloads/usa/en/c/cert_ESSNetwork_XRX07001_v1.pdf CONFIRM www.xerox.com
Sun Solaris OpenSSL Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
404 Not Found CONFIRM kolab.org Patch
Gentoo Linux Documentation -- OpenSSL: Multiple vulnerabilities GENTOO security.gentoo.org
Gentoo update for emul-linux-x86-baselibs - Advisories - Secunia SECUNIA secunia.com
Gentoo Linux Documentation -- AMD64 x86 emulation base libraries: OpenSSL multiple vulnerabilities GENTOO www.gentoo.org
IT Resource Center - login / register HP itrc.hp.com
Slackware update for openssl - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
SSRT071304 HP www2.itrc.hp.com
Advisories - Mandriva Linux MANDRIVA www.mandriva.com
Download Patch ESX-3069097 for VMware ESX Server 3.0.1 CONFIRM www.vmware.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
201531 SUNALERT sunsolve.sun.com
Red Hat Network Satellite Server Update for Solaris Client - Advisories - Community SECUNIA secunia.com
Nortel: Technical Support CONFIRM www130.nortelnetworks.com
Gentoo ltsp Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com SECUNIA secunia.com
SecurityFocus BUGTRAQ www.securityfocus.com
IBM X-Force Exchange XF exchange.xforce.ibmcloud.com
Oracle January 2007 Security Update Multiple Vulnerabilities BID www.securityfocus.com
Webmail - OVH VUPEN www.vupen.com
FileZilla / FileZilla Server Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Patch, Vendor Advisory
HP-UX update for Apache - Advisories - Secunia SECUNIA secunia.com
VMware ESX Server 2.0.2 Upgrade Patch 4 (for 2.0.2 Systems) CONFIRM www.vmware.com
ASA-2006-220 (RHSA-2006-0695) CONFIRM support.avaya.com
NetBSD-SA2008-007 NETBSD ftp.netbsd.org
Avaya Products OpenSSL Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
Webmail - OVH VUPEN www.vupen.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH VUPEN www.vupen.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

OrganizationPublishedContributorStatement
Red Hat2007-03-14Mark J CoxRed Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Legacy QID Mappings

  • 390284 Oracle Managed Virtualization (VM) Server for x86 Security Update for Open Secure Sockets Layer (OpenSSL) (OVMSA-2023-0013)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report