CVE-2006-4343

Summary

CVECVE-2006-4343
StatePUBLISHED
Assignerredhat
Source PriorityCVE Program / NVD first with legacy fallback
Published2006-09-28 18:07:00 UTC
Updated2026-04-23 00:35:47 UTC
DescriptionThe get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.

Risk And Classification

Primary CVSS: v2.0 4.3 from [email protected]

AV:N/AC:M/Au:N/C:N/I:N/A:P

Problem Types: CWE-476 | n/a

CVSS v2.0 Breakdown

Access Vector
Network
Access Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial

AV:N/AC:M/Au:N/C:N/I:N/A:P

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Canonical Ubuntu Linux 5.04 All All All
Operating System Canonical Ubuntu Linux 5.10 All All All
Operating System Canonical Ubuntu Linux 6.06 All All All
Operating System Debian Debian Linux 3.1 All All All
Application Openssl Openssl 0.9.7 All All All
Application Openssl Openssl 0.9.7a All All All
Application Openssl Openssl 0.9.7b All All All
Application Openssl Openssl 0.9.7c All All All
Application Openssl Openssl 0.9.7d All All All
Application Openssl Openssl 0.9.7e All All All
Application Openssl Openssl 0.9.7f All All All
Application Openssl Openssl 0.9.7g All All All
Application Openssl Openssl 0.9.7h All All All
Application Openssl Openssl 0.9.7i All All All
Application Openssl Openssl 0.9.7j All All All
Application Openssl Openssl 0.9.7k All All All
Application Openssl Openssl 0.9.8 All All All
Application Openssl Openssl 0.9.8a All All All
Application Openssl Openssl 0.9.8b All All All
Application Openssl Openssl 0.9.8c All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Na N/a affected n/a Not specified

References

ReferenceSourceLinkTags
Cisco Security Response: Multiple Vulnerabilities in OpenSSL Library  [Cisco GSS 4400 Series Global Site Selector Appliances] - Cisco Systems af854a3a-2127-422b-91ae-364da2661108 www.cisco.com Third Party Advisory
Ingate Firewall and SIParator Multiple Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Mandriva update for MySQL - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Kolab Server Multiple Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
[#RPL-613] openssl vulnerabilities including remote unauthorized access: CVE-2006-2937 CVE-2006-2940 CVE-2006-3738 CVE-2006-4343 - rPath JIRA af854a3a-2127-422b-91ae-364da2661108 issues.rpath.com Broken Link
Webmail - OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
VMware Player Release Notes af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
Gentoo update for emul-linux-x86-baselibs - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
HP-UX update for OpenSSL - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Debian update for openssl - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
SecurityTracker.com Archives - Oracle Database and Other Products Have 52 Unspecified Vulnerabilities With Unspecified Impact af854a3a-2127-422b-91ae-364da2661108 securitytracker.com Third Party Advisory, VDB Entry
Advisories - Mandriva Linux af854a3a-2127-422b-91ae-364da2661108 www.mandriva.com Third Party Advisory
[Full-disclosure] [SECURITY] OpenSSL 0.9.8d and 0.9.7l released af854a3a-2127-422b-91ae-364da2661108 lists.grok.org.uk Mailing List, Third Party Advisory
Oracle Products Multiple Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
[Security-announce] VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues af854a3a-2127-422b-91ae-364da2661108 lists.vmware.com Mailing List, Third Party Advisory
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
rPath update for openssl - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
IBM HMC OpenSSH / OpenSSL Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
patches.sgi.com/support/free/security/advisories/20061001-01-P.asc af854a3a-2127-422b-91ae-364da2661108 patches.sgi.com Third Party Advisory
www2.itrc.hp.com/service/cki/docDisplay.do af854a3a-2127-422b-91ae-364da2661108 www2.itrc.hp.com Broken Link
Gentoo update for openssl - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
'[security bulletin] HPSBOV02683 SSRT090208 rev.1 - HP Secure Web Server (SWS) for OpenVMS running Ap' - MARC af854a3a-2127-422b-91ae-364da2661108 marc.info Mailing List, Third Party Advisory
Debian update for openssl096 - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Download Patch ESX-3069097 for VMware ESX Server 3.0.1 af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
OpenBSD 4.0 errata af854a3a-2127-422b-91ae-364da2661108 openbsd.org Third Party Advisory
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
Mandriva update for openssl - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
OpenSSL SSLv2 Null Pointer Dereference Client Denial of Service Vulnerability af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com Patch, Third Party Advisory, VDB Entry
ASA-2006-260 HP-UX OpenSSL Denial of Service (DoS), Increase Privilige (HPSBUX02174) af854a3a-2127-422b-91ae-364da2661108 support.avaya.com Third Party Advisory
Mandriva update for ntp - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Support af854a3a-2127-422b-91ae-364da2661108 www.redhat.com Third Party Advisory
IT Resource Center - login / register af854a3a-2127-422b-91ae-364da2661108 itrc.hp.com Broken Link
Avaya Products OpenSSL Multiple Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Webmail - OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
Trustix updates for openssh and openssl - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
VMware Server Release Notes af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
www.osvdb.org/29263 af854a3a-2127-422b-91ae-364da2661108 www.osvdb.org Broken Link
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
VMSA-2008-0005.1 - VMware af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
OpenBSD update for OpenSSL - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Gentoo Linux Documentation -- OpenSSL: Multiple vulnerabilities af854a3a-2127-422b-91ae-364da2661108 security.gentoo.org Third Party Advisory
APPLE-SA-2006-11-28 Security Update 2006-007 af854a3a-2127-422b-91ae-364da2661108 lists.apple.com Mailing List, Third Party Advisory
SUSE update for openssl - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
HP System Management Homepage Apache and OpenSSL Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Oracle January 2007 Security Update Multiple Vulnerabilities af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com Third Party Advisory, VDB Entry
Serv-U FTP Server OpenSSL Multiple Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
VMWare ESX Server Multiple Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
www.xerox.com/downloads/usa/en/c/cert_ESSNetwork_XRX07001_v1.pdf af854a3a-2127-422b-91ae-364da2661108 www.xerox.com Third Party Advisory
VMware ESX Server 2.1.3 Upgrade Patch 4 (for 2.1.3 Systems) af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
SecurityTracker.com Archives - OpenSSL ASN.1 Bugs, SSL_get_shared_ciphers() Buffer Overflow, and SSLv2 Client Error Lets Remote Users Denial of Service or Execute Arbitrary Code af854a3a-2127-422b-91ae-364da2661108 securitytracker.com Third Party Advisory, VDB Entry
VMware ACE Release Notes af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
Advisories - Mandriva Linux af854a3a-2127-422b-91ae-364da2661108 www.mandriva.com Third Party Advisory
OpenPKG Corporation: Security: Security Advisories af854a3a-2127-422b-91ae-364da2661108 www.openpkg.org Third Party Advisory
Xerox ESS/ Network Controller OpenSSL Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Download Patch ESX-9986131 for VMware ESX Server 3.0.1 af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
Webmail - OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
www.trustix.org/errata/2006/0054 af854a3a-2127-422b-91ae-364da2661108 www.trustix.org Broken Link
SourceForge.net: SysAdmin Tools from ITeF!x: Files af854a3a-2127-422b-91ae-364da2661108 sourceforge.net Broken Link
Cisco Products OpenSSL Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
NetBSD update for OpenSSL - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Repository / Oval Repository af854a3a-2127-422b-91ae-364da2661108 oval.cisecurity.org Third Party Advisory
VMware ESX Server 2.0.2 Upgrade Patch 4 (for 2.0.2 Systems) af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
Slackware update for openssl - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
SecurityFocus af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com
Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
FileZilla / FileZilla Server Multiple Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
rhn.redhat.com | Red Hat Support af854a3a-2127-422b-91ae-364da2661108 www.redhat.com Third Party Advisory
Gentoo Linux Documentation -- AMD64 x86 emulation base libraries: OpenSSL multiple vulnerabilities af854a3a-2127-422b-91ae-364da2661108 www.gentoo.org Third Party Advisory
OpenSSL < 0.9.7l / 0.9.8d SSLv2 Client Crash Exploit af854a3a-2127-422b-91ae-364da2661108 www.exploit-db.com Third Party Advisory, VDB Entry
About the security content of Security Update 2006-007 af854a3a-2127-422b-91ae-364da2661108 docs.info.apple.com Third Party Advisory
Cisco Products OpenSSL Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
VMware Workstation 6 Release Notes af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
Advisories - Mandriva Linux af854a3a-2127-422b-91ae-364da2661108 www.mandriva.com Broken Link
security.freebsd.org/advisories/FreeBSD-SA-06:23.openssl.asc af854a3a-2127-422b-91ae-364da2661108 security.freebsd.org Third Party Advisory
OpenSSL Multiple Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Webmail - OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
VMware Player Release Notes af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
ASA-2006-220 (RHSA-2006-0695) af854a3a-2127-422b-91ae-364da2661108 support.avaya.com Third Party Advisory
Sun Grid Engine Multiple OpenSSL Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Oracle Critical Patch Update - January 2007 af854a3a-2127-422b-91ae-364da2661108 www.oracle.com Third Party Advisory
sunsolve.sun.com/search/document.do af854a3a-2127-422b-91ae-364da2661108 sunsolve.sun.com Broken Link
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
Ubuntu update for openssl - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
SecurityFocus af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com
US-CERT Vulnerability Note VU#386964 af854a3a-2127-422b-91ae-364da2661108 www.kb.cert.org Patch, Third Party Advisory, US Government Resource
SnapGear Multiple Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
SecurityFocus af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com
Security Announcement af854a3a-2127-422b-91ae-364da2661108 www.novell.com Broken Link
IBM X-Force Exchange af854a3a-2127-422b-91ae-364da2661108 exchange.xforce.ibmcloud.com Third Party Advisory, VDB Entry
rPath update for openssl - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Debian -- Security Information -- DSA-1195-1 openssl096 af854a3a-2127-422b-91ae-364da2661108 www.debian.org Third Party Advisory
Red Hat Network Satellite Server Update for Solaris Client - Advisories - Community af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
VMware Workstation 5.5 Release Notes af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
Serv-U Release Notes - Current af854a3a-2127-422b-91ae-364da2661108 www.serv-u.com Third Party Advisory
ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.asc af854a3a-2127-422b-91ae-364da2661108 ftp.netbsd.org Third Party Advisory
cwRsync OpenSSL Vulnerabilities and OpenSSH Weakness - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Webmail - OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
Webmail - OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
www.openssl.org/news/secadv_20060928.txt af854a3a-2127-422b-91ae-364da2661108 www.openssl.org Patch, Third Party Advisory
SUSE updates for openssh, openssl, and bind9 - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
usn/usn-353-1 - Ubuntu: Linux for human beings af854a3a-2127-422b-91ae-364da2661108 www.ubuntu.com Third Party Advisory
Cisco - Networking, Cloud, and Cybersecurity Solutions af854a3a-2127-422b-91ae-364da2661108 www.cisco.com Third Party Advisory
SecurityFocus af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com
Release notice for Ingate Firewall® 4.5.2 and Ingate SIParator® 4.5.2 af854a3a-2127-422b-91ae-364da2661108 www.ingate.com Broken Link
Security Announcement af854a3a-2127-422b-91ae-364da2661108 www.novell.com Broken Link
US-CERT Technical Cyber Security Alert TA06-333A -- Apple Releases Security Update to Address Multiple Vulnerabilities af854a3a-2127-422b-91ae-364da2661108 www.us-cert.gov Third Party Advisory, US Government Resource
HP Insight Management Agents SSL Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
#102668: Security Vulnerabilities In OpenSSL Affect Sun Grid Engine 5.3 and N1 Grid Engine 6.0 af854a3a-2127-422b-91ae-364da2661108 sunsolve.sun.com Broken Link
Sun Solaris OpenSSL Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
VMware Server 1.0.5 and Workstation 6.0.3 Multiple Vulnerabilities af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com Third Party Advisory, VDB Entry
IT Resource Center - login / register af854a3a-2127-422b-91ae-364da2661108 itrc.hp.com Broken Link
OpenVPN 2.0.x Change Log af854a3a-2127-422b-91ae-364da2661108 openvpn.net Third Party Advisory
Webmail - OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
Avaya PDS HP-UX Secure Shell / OpenSSL Multiple Vulnerabilities - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
HPSBMA02250 SSRT061275 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Execution of Arbitrary Code and Denial of Service (DoS) - c01118771 - HP Business Support Center af854a3a-2127-422b-91ae-364da2661108 h20000.www2.hp.com Broken Link
The Slackware Linux Project: Slackware Security Advisories af854a3a-2127-422b-91ae-364da2661108 slackware.com Mailing List, Third Party Advisory
VMware ESX Server 2.5.4 Upgrade Patch 3 (for 2.5.4 Systems Only) af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
Red Hat update for openssl - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Repository / Oval Repository af854a3a-2127-422b-91ae-364da2661108 oval.cisecurity.org Third Party Advisory
404 Not Found af854a3a-2127-422b-91ae-364da2661108 kolab.org Broken Link
Debian -- Security Information -- DSA-1185-2 openssl af854a3a-2127-422b-91ae-364da2661108 www.debian.org Third Party Advisory
FreeBSD update for openssl - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
#102711: Security Vulnerabilities in OpenSSL May Lead to a Denial of Service (DoS) to Applications or Execution of Arbitrary Code With Elevated Privileges af854a3a-2127-422b-91ae-364da2661108 sunsolve.sun.com Broken Link
HP-UX update for Apache - Advisories - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Third Party Advisory
Webmail - OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com Permissions Required, Third Party Advisory
VMware ESX Server 2.5.3 Upgrade Patch 6 (for 2.5.3 Systems) af854a3a-2127-422b-91ae-364da2661108 www.vmware.com Third Party Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

OrganizationPublishedContributorStatement
Red Hat2007-03-14Mark J CoxRed Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Legacy QID Mappings

  • 390284 Oracle Managed Virtualization (VM) Server for x86 Security Update for Open Secure Sockets Layer (OpenSSL) (OVMSA-2023-0013)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report