CVE-2006-2940
Last modified
CVE-2006-2940 is a vulnerability of currently unknown severity. OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra time to process when using RSA signature verification.. EPSS estimates a 4.90% chance of exploitation in the next 30 days.
Description
OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra time to process when using RSA signature verification.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | 0.9.1c |
| Openssl | Openssl | 0.9.2b |
| Openssl | Openssl | 0.9.3 |
| Openssl | Openssl | 0.9.3a |
| Openssl | Openssl | 0.9.4 |
| Openssl | Openssl | 0.9.5 |
| Openssl | Openssl | 0.9.5a |
| Openssl | Openssl | 0.9.6 |
| Openssl | Openssl | 0.9.6a |
| Openssl | Openssl | 0.9.6b |
| Openssl | Openssl | 0.9.6c |
| Openssl | Openssl | 0.9.6d |
| Openssl | Openssl | 0.9.6e |
| Openssl | Openssl | 0.9.6f |
| Openssl | Openssl | 0.9.6g |
| Openssl | Openssl | 0.9.6h |
| Openssl | Openssl | 0.9.6i |
| Openssl | Openssl | 0.9.6j |
| Openssl | Openssl | 0.9.6k |
| Openssl | Openssl | 0.9.6l |
| Openssl | Openssl | 0.9.6m |
| Openssl | Openssl | 0.9.7 |
| Openssl | Openssl | 0.9.7a |
| Openssl | Openssl | 0.9.7b |
| Openssl | Openssl | 0.9.7c |
| Openssl | Openssl | 0.9.7d |
| Openssl | Openssl | 0.9.7e |
| Openssl | Openssl | 0.9.7f |
| Openssl | Openssl | 0.9.7g |
| Openssl | Openssl | 0.9.7h |
| Openssl | Openssl | 0.9.7i |
| Openssl | Openssl | 0.9.7j |
| Openssl | Openssl | 0.9.7k |
| Openssl | Openssl | 0.9.8 |
| Openssl | Openssl | 0.9.8a |
| Openssl | Openssl | 0.9.8b |
| Openssl | Openssl | 0.9.8c |
References
- http://secunia.com/advisories/22094Vendor Advisory
- http://secunia.com/advisories/22116Vendor Advisory
- http://secunia.com/advisories/22130Vendor Advisory
- http://secunia.com/advisories/22165Vendor Advisory
- http://secunia.com/advisories/22166Vendor Advisory
- http://secunia.com/advisories/22172Vendor Advisory
- http://secunia.com/advisories/22186Vendor Advisory
- http://secunia.com/advisories/22193Vendor Advisory
- http://secunia.com/advisories/22207Vendor Advisory
- http://secunia.com/advisories/22212Vendor Advisory
- http://secunia.com/advisories/22216Vendor Advisory
- http://secunia.com/advisories/22220Vendor Advisory
- http://secunia.com/advisories/22240Vendor Advisory
- http://secunia.com/advisories/22259Vendor Advisory
- http://secunia.com/advisories/22260Vendor Advisory
- http://secunia.com/advisories/22284Vendor Advisory
- http://secunia.com/advisories/22330Vendor Advisory
- http://secunia.com/advisories/22385Vendor Advisory
- http://secunia.com/advisories/22460Vendor Advisory
- http://secunia.com/advisories/22500Vendor Advisory
- http://secunia.com/advisories/22544Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0695.htmlVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA06-333A.htmlUS Government Resource
- http://secunia.com/advisories/22094Vendor Advisory
- http://secunia.com/advisories/22116Vendor Advisory
- http://secunia.com/advisories/22130Vendor Advisory
- http://secunia.com/advisories/22165Vendor Advisory
- http://secunia.com/advisories/22166Vendor Advisory
- http://secunia.com/advisories/22172Vendor Advisory
- http://secunia.com/advisories/22186Vendor Advisory
- http://secunia.com/advisories/22193Vendor Advisory
- http://secunia.com/advisories/22207Vendor Advisory
- http://secunia.com/advisories/22212Vendor Advisory
- http://secunia.com/advisories/22216Vendor Advisory
- http://secunia.com/advisories/22220Vendor Advisory
- http://secunia.com/advisories/22240Vendor Advisory
- http://secunia.com/advisories/22259Vendor Advisory
- http://secunia.com/advisories/22260Vendor Advisory
- http://secunia.com/advisories/22284Vendor Advisory
- http://secunia.com/advisories/22330Vendor Advisory
- http://secunia.com/advisories/22385Vendor Advisory
- http://secunia.com/advisories/22460Vendor Advisory
- http://secunia.com/advisories/22500Vendor Advisory
- http://secunia.com/advisories/22544Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0695.htmlVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA06-333A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-2940?
How severe is CVE-2006-2940?
How do I fix CVE-2006-2940?
Are you affected by CVE-2006-2940?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
