Ad

CVE-2006-2937

NONE EPSS 5.11%
Updated Apr 23, 2026
OpenSSL
Parameter Value
Type CWE-399 (Resource Management Errors)
Vendor OpenSSL
Public PoC No

OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition.

Vulnerable Products 16

Configuration From (including) Up to (excluding)
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7b:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7c:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7d:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7e:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7f:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7g:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7h:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7i:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7j:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7k:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*

References 136

ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.asc
secalert@redhat.com
ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc
secalert@redhat.com
http://docs.info.apple.com/article.html?artnum=304829
secalert@redhat.com
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771
secalert@redhat.com
http://issues.rpath.com/browse/RPL-613
secalert@redhat.com
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100
secalert@redhat.com
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540
secalert@redhat.com
http://kolab.org/security/kolab-vendor-notice-11.txt
secalert@redhat.com
http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html
secalert@redhat.com
http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049715.html
secalert@redhat.com
http://lists.vmware.com/pipermail/security-announce/2008/000008.html
secalert@redhat.com
http://marc.info/?l=bind-announce&m=116253119512445&w=2
secalert@redhat.com
http://marc.info/?l=bugtraq&m=130497311408250&w=2
secalert@redhat.com
http://openbsd.org/errata.html#openssl2
secalert@redhat.com
http://openvpn.net/changelog.html
secalert@redhat.com
http://secunia.com/advisories/22094
secalert@redhat.com
http://secunia.com/advisories/22116
secalert@redhat.com
http://secunia.com/advisories/22130
secalert@redhat.com
http://secunia.com/advisories/22165
secalert@redhat.com
http://secunia.com/advisories/22166
secalert@redhat.com
http://secunia.com/advisories/22172
secalert@redhat.com
http://secunia.com/advisories/22186
secalert@redhat.com
http://secunia.com/advisories/22193
secalert@redhat.com
http://secunia.com/advisories/22207
secalert@redhat.com
http://secunia.com/advisories/22212
secalert@redhat.com
http://secunia.com/advisories/22216
secalert@redhat.com
http://secunia.com/advisories/22220
secalert@redhat.com
http://secunia.com/advisories/22240
secalert@redhat.com
http://secunia.com/advisories/22259
secalert@redhat.com
http://secunia.com/advisories/22260
secalert@redhat.com
http://secunia.com/advisories/22284
secalert@redhat.com
http://secunia.com/advisories/22298
secalert@redhat.com
http://secunia.com/advisories/22330
secalert@redhat.com
http://secunia.com/advisories/22385
secalert@redhat.com
http://secunia.com/advisories/22460
secalert@redhat.com
http://secunia.com/advisories/22487
secalert@redhat.com
http://secunia.com/advisories/22544
secalert@redhat.com
http://secunia.com/advisories/22626
secalert@redhat.com
http://secunia.com/advisories/22671
secalert@redhat.com
http://secunia.com/advisories/22758
secalert@redhat.com
http://secunia.com/advisories/22772
secalert@redhat.com
http://secunia.com/advisories/22799
secalert@redhat.com
http://secunia.com/advisories/23038
secalert@redhat.com
http://secunia.com/advisories/23131
secalert@redhat.com
http://secunia.com/advisories/23155
secalert@redhat.com
http://secunia.com/advisories/23280
secalert@redhat.com
http://secunia.com/advisories/23309
secalert@redhat.com
http://secunia.com/advisories/23340
secalert@redhat.com
http://secunia.com/advisories/23351
secalert@redhat.com
http://secunia.com/advisories/23680
secalert@redhat.com
http://secunia.com/advisories/23915
secalert@redhat.com
http://secunia.com/advisories/24930
secalert@redhat.com
http://secunia.com/advisories/24950
secalert@redhat.com
http://secunia.com/advisories/25889
secalert@redhat.com
http://secunia.com/advisories/26329
secalert@redhat.com
http://secunia.com/advisories/30124
secalert@redhat.com
http://secunia.com/advisories/31492
secalert@redhat.com
http://secunia.com/advisories/31531
secalert@redhat.com
http://security.freebsd.org/advisories/FreeBSD-SA-06:23.openssl.asc
secalert@redhat.com
http://security.gentoo.org/glsa/glsa-200610-11.xml
secalert@redhat.com
http://securitytracker.com/id?1016943
secalert@redhat.com
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackwar…
secalert@redhat.com
http://sourceforge.net/project/shownotes.php?release_id=461863&group_id=69227
secalert@redhat.com
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102668-1
secalert@redhat.com
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102747-1
secalert@redhat.com
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200585-1
secalert@redhat.com
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201534-1
secalert@redhat.com
http://support.attachmate.com/techdocs/2374.html
secalert@redhat.com
http://support.avaya.com/elmodocs2/security/ASA-2006-220.htm
secalert@redhat.com
http://support.avaya.com/elmodocs2/security/ASA-2006-260.htm
secalert@redhat.com
http://www.arkoon.fr/upload/alertes/37AK-2006-06-FR-1.1_FAST360_OPENSSL_ASN1.pdf
secalert@redhat.com
http://www.arkoon.fr/upload/alertes/41AK-2006-08-FR-1.1_SSL360_OPENSSL_ASN1.pdf
secalert@redhat.com
http://www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_re…
secalert@redhat.com
http://www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtml
secalert@redhat.com
http://www.debian.org/security/2006/dsa-1185
secalert@redhat.com
http://www.f-secure.com/security/fsc-2006-6.shtml
secalert@redhat.com
http://www.gentoo.org/security/en/glsa/glsa-200612-11.xml
secalert@redhat.com
http://www.kb.cert.org/vuls/id/247744
secalert@redhat.com
http://www.mandriva.com/security/advisories?name=MDKSA-2006:172
secalert@redhat.com
http://www.mandriva.com/security/advisories?name=MDKSA-2006:177
secalert@redhat.com
http://www.mandriva.com/security/advisories?name=MDKSA-2006:178
secalert@redhat.com
http://www.novell.com/linux/security/advisories/2006_24_sr.html
secalert@redhat.com
http://www.novell.com/linux/security/advisories/2006_58_openssl.html
secalert@redhat.com
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.021-openssl.html
secalert@redhat.com
http://www.openssl.org/news/secadv_20060928.txt
secalert@redhat.com
http://www.osvdb.org/29260
secalert@redhat.com
http://www.redhat.com/support/errata/RHSA-2006-0695.html
secalert@redhat.com
http://www.redhat.com/support/errata/RHSA-2008-0629.html
secalert@redhat.com
http://www.securityfocus.com/archive/1/447318/100/0/threaded
secalert@redhat.com
http://www.securityfocus.com/archive/1/447393/100/0/threaded
secalert@redhat.com
http://www.securityfocus.com/archive/1/456546/100/200/threaded
secalert@redhat.com
http://www.securityfocus.com/archive/1/489739/100/0/threaded
secalert@redhat.com
http://www.securityfocus.com/bid/20248
secalert@redhat.com
http://www.securityfocus.com/bid/28276
secalert@redhat.com
http://www.serv-u.com/releasenotes/
secalert@redhat.com
http://www.trustix.org/errata/2006/0054
secalert@redhat.com
http://www.ubuntu.com/usn/usn-353-1
secalert@redhat.com
http://www.us-cert.gov/cas/techalerts/TA06-333A.html
secalert@redhat.com
http://www.vmware.com/security/advisories/VMSA-2008-0005.html
secalert@redhat.com
http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html
secalert@redhat.com
http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html
secalert@redhat.com
http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html
secalert@redhat.com
http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html
secalert@redhat.com
http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html
secalert@redhat.com
http://www.vmware.com/support/player/doc/releasenotes_player.html
secalert@redhat.com
http://www.vmware.com/support/player2/doc/releasenotes_player2.html
secalert@redhat.com
http://www.vmware.com/support/server/doc/releasenotes_server.html
secalert@redhat.com
http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html
secalert@redhat.com
http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html
secalert@redhat.com
http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html
secalert@redhat.com
http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/3820
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/3860
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/3869
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/3902
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/3936
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/4019
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/4036
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/4264
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/4327
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/4329
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/4401
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/4417
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/4750
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/4761
secalert@redhat.com
http://www.vupen.com/english/advisories/2006/4980
secalert@redhat.com
http://www.vupen.com/english/advisories/2007/0343
secalert@redhat.com
http://www.vupen.com/english/advisories/2007/1401
secalert@redhat.com
http://www.vupen.com/english/advisories/2007/2315
secalert@redhat.com
http://www.vupen.com/english/advisories/2007/2783
secalert@redhat.com
http://www.vupen.com/english/advisories/2008/0905/references
secalert@redhat.com
http://www.vupen.com/english/advisories/2008/2396
secalert@redhat.com
http://www.xerox.com/downloads/usa/en/c/cert_ESSNetwork_XRX07001_v1.pdf
secalert@redhat.com
https://exchange.xforce.ibmcloud.com/vulnerabilities/29228
secalert@redhat.com
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%…
secalert@redhat.com
https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144
secalert@redhat.com