CVE-2006-2940

N/A Unknown
Published: September 28, 2006 Modified: April 23, 2026
View on NVD

Description

OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra time to process when using RSA signature verification.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://issues.rpath.com/browse/RPL-613
Source: secalert@redhat.com
http://openbsd.org/errata.html#openssl2
Source: secalert@redhat.com
http://openvpn.net/changelog.html
Source: secalert@redhat.com
http://secunia.com/advisories/22094
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22116
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22130
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22165
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22166
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22172
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22186
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22193
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22207
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22212
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22216
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22220
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22240
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22259
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22260
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22284
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22298
Source: secalert@redhat.com
http://secunia.com/advisories/22330
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22385
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22460
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22487
Source: secalert@redhat.com
http://secunia.com/advisories/22500
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22544
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/22626
Source: secalert@redhat.com
http://secunia.com/advisories/22671
Source: secalert@redhat.com
http://secunia.com/advisories/22758
Source: secalert@redhat.com
http://secunia.com/advisories/22772
Source: secalert@redhat.com
http://secunia.com/advisories/22799
Source: secalert@redhat.com
http://secunia.com/advisories/23038
Source: secalert@redhat.com
http://secunia.com/advisories/23155
Source: secalert@redhat.com
http://secunia.com/advisories/23280
Source: secalert@redhat.com
http://secunia.com/advisories/23309
Source: secalert@redhat.com
http://secunia.com/advisories/23340
Source: secalert@redhat.com
http://secunia.com/advisories/23351
Source: secalert@redhat.com
http://secunia.com/advisories/23680
Source: secalert@redhat.com
http://secunia.com/advisories/23794
Source: secalert@redhat.com
http://secunia.com/advisories/23915
Source: secalert@redhat.com
http://secunia.com/advisories/24930
Source: secalert@redhat.com
http://secunia.com/advisories/24950
Source: secalert@redhat.com
http://secunia.com/advisories/25889
Source: secalert@redhat.com
http://secunia.com/advisories/26329
Source: secalert@redhat.com
http://secunia.com/advisories/26893
Source: secalert@redhat.com
http://secunia.com/advisories/30124
Source: secalert@redhat.com
http://secunia.com/advisories/31492
Source: secalert@redhat.com
http://secunia.com/advisories/31531
Source: secalert@redhat.com
http://securitytracker.com/id?1016943
Source: secalert@redhat.com
http://securitytracker.com/id?1017522
Source: secalert@redhat.com
http://www.osvdb.org/29261
Source: secalert@redhat.com
http://www.redhat.com/support/errata/RHSA-2006-0695.html
Source: secalert@redhat.com
Vendor Advisory
http://www.securityfocus.com/bid/20247
Source: secalert@redhat.com
http://www.securityfocus.com/bid/22083
Source: secalert@redhat.com
http://www.securityfocus.com/bid/28276
Source: secalert@redhat.com
http://www.serv-u.com/releasenotes/
Source: secalert@redhat.com
http://www.trustix.org/errata/2006/0054
Source: secalert@redhat.com
http://www.ubuntu.com/usn/usn-353-1
Source: secalert@redhat.com
http://www.ubuntu.com/usn/usn-353-2
Source: secalert@redhat.com
http://www.us-cert.gov/cas/techalerts/TA06-333A.html
Source: secalert@redhat.com
US Government Resource
https://issues.rpath.com/browse/RPL-1633
Source: secalert@redhat.com
http://docs.info.apple.com/article.html?artnum=304829
Source: af854a3a-2127-422b-91ae-364da2661108
http://issues.rpath.com/browse/RPL-613
Source: af854a3a-2127-422b-91ae-364da2661108
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100
Source: af854a3a-2127-422b-91ae-364da2661108
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540
Source: af854a3a-2127-422b-91ae-364da2661108
http://kolab.org/security/kolab-vendor-notice-11.txt
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bind-announce&m=116253119512445&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=130497311408250&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://openbsd.org/errata.html#openssl2
Source: af854a3a-2127-422b-91ae-364da2661108
http://openvpn.net/changelog.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22094
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22116
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22130
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22165
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22166
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22172
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22186
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22193
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22207
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22212
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22216
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22220
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22240
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22259
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22260
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22284
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22298
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22330
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22385
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22460
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22487
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22500
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22544
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/22626
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22671
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22758
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22772
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22799
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23038
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23155
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23280
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23309
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23340
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23351
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23680
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23794
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23915
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24930
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24950
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25889
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26329
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26893
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/30124
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/31492
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/31531
Source: af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-200610-11.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1016943
Source: af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1017522
Source: af854a3a-2127-422b-91ae-364da2661108
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102668-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102747-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200585-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201534-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://support.attachmate.com/techdocs/2374.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://support.avaya.com/elmodocs2/security/ASA-2006-220.htm
Source: af854a3a-2127-422b-91ae-364da2661108
http://support.avaya.com/elmodocs2/security/ASA-2006-260.htm
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2006/dsa-1185
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2006/dsa-1195
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.gentoo.org/security/en/glsa/glsa-200612-11.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2006:172
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2006:177
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2006:178
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.novell.com/linux/security/advisories/2006_24_sr.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.openssl.org/news/secadv_20060928.txt
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/29261
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2006-0695.html
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0629.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/447318/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/447393/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/456546/100/200/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/489739/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/20247
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/22083
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/28276
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.serv-u.com/releasenotes/
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.trustix.org/errata/2006/0054
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-353-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-353-2
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.uniras.gov.uk/niscc/docs/re-20060928-00661.pdf?lang=en
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.us-cert.gov/cas/techalerts/TA06-333A.html
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
http://www.vmware.com/security/advisories/VMSA-2008-0005.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/support/player/doc/releasenotes_player.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/support/server/doc/releasenotes_server.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3820
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3860
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3869
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3902
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3936
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4019
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4036
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4264
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4327
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4329
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4401
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4417
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4750
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4980
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/0343
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/1401
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/2315
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/2783
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2008/0905/references
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2008/2396
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/29230
Source: af854a3a-2127-422b-91ae-364da2661108
https://issues.rpath.com/browse/RPL-1633
Source: af854a3a-2127-422b-91ae-364da2661108

284 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.9%
86th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

openssl