CVE-2006-4343
medium · 4.3The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.
4.3
CVSS
19.1%
EPSS (exploit prob.)
97th
EPSS percentile
2006-09-28
Published
AV:N/AC:M/Au:N/C:N/I:N/A:P
Weaknesses
CWE-476
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| openssl | openssl | 0.9.7 |
| openssl | openssl | 0.9.7a |
| openssl | openssl | 0.9.7b |
| openssl | openssl | 0.9.7c |
| openssl | openssl | 0.9.7d |
| openssl | openssl | 0.9.7e |
| openssl | openssl | 0.9.7f |
| openssl | openssl | 0.9.7g |
| openssl | openssl | 0.9.7h |
| openssl | openssl | 0.9.7i |
| openssl | openssl | 0.9.7j |
| openssl | openssl | 0.9.7k |
| openssl | openssl | 0.9.8 |
| openssl | openssl | 0.9.8a |
| openssl | openssl | 0.9.8b |
| openssl | openssl | 0.9.8c |
| debian | debian_linux | 3.1 |
| canonical | ubuntu_linux | 5.04 |
| canonical | ubuntu_linux | 5.10 |
| canonical | ubuntu_linux | 6.06 |
Check a specific version with /api/v1/cve/match.
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.asc
- ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc
- http://docs.info.apple.com/article.html?artnum=304829
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771
- http://issues.rpath.com/browse/RPL-613
- http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100
- http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540
- http://kolab.org/security/kolab-vendor-notice-11.txt
- http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049715.html
- http://lists.vmware.com/pipermail/security-announce/2008/000008.html
- http://marc.info/?l=bugtraq&m=130497311408250&w=2
- http://openbsd.org/errata.html#openssl2
- http://openvpn.net/changelog.html
- http://secunia.com/advisories/22094
- http://secunia.com/advisories/22116
- http://secunia.com/advisories/22130
- http://secunia.com/advisories/22165
- http://secunia.com/advisories/22166
- http://secunia.com/advisories/22172
- http://secunia.com/advisories/22186
- http://secunia.com/advisories/22193
- http://secunia.com/advisories/22207
- http://secunia.com/advisories/22212
- http://secunia.com/advisories/22216
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-4343