CVE-2006-4343
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 19.07% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- openssl/openssl · debian/debian linux · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.ascThird Party Advisory
- ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.ascThird Party Advisory
- http://docs.info.apple.com/article.html?artnum=304829Third Party Advisory
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771Broken Link
- http://issues.rpath.com/browse/RPL-613Broken Link
- http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100Broken Link
- http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540Broken Link
- http://kolab.org/security/kolab-vendor-notice-11.txtBroken Link
- http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.htmlMailing List, Third Party Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049715.htmlMailing List, Third Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2008/000008.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=130497311408250&w=2Mailing List, Third Party Advisory
- http://openbsd.org/errata.html#openssl2Third Party Advisory
- http://openvpn.net/changelog.htmlThird Party Advisory
- http://secunia.com/advisories/22094Third Party Advisory
- http://secunia.com/advisories/22116Third Party Advisory
- http://secunia.com/advisories/22130Third Party Advisory
- http://secunia.com/advisories/22165Third Party Advisory
- http://secunia.com/advisories/22166Third Party Advisory
- http://secunia.com/advisories/22172Third Party Advisory
- http://secunia.com/advisories/22186Third Party Advisory
- http://secunia.com/advisories/22193Third Party Advisory
- http://secunia.com/advisories/22207Third Party Advisory
- http://secunia.com/advisories/22212Third Party Advisory
- http://secunia.com/advisories/22216Third Party Advisory
- http://secunia.com/advisories/22220Third Party Advisory
- http://secunia.com/advisories/22240Third Party Advisory
- http://secunia.com/advisories/22259Third Party Advisory
- http://secunia.com/advisories/22260Third Party Advisory
- http://secunia.com/advisories/22284Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.