SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#247744

OpenSSL may fail to properly parse invalid ASN.1 structures

Overview

A vulnerability in OpenSSL may allow an attacker to create a denial-of-service condition.

I. Description

OpenSSL is an Open Source toolkit that implements the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols.

When parsing certain invalid ASN.1 structures, OpenSSL may mishandle an error condition, resulting in an infinite loop. By triggering the infinite loop, an attacker may be able to create a denial-of-service condition.

II. Impact

A remote, unauthenticated attacker may be able create a denial-of-service condition.

III. Solution

See the systems affected section of this document for information about specific vendors. Users who compile OpenSSL from source are encouraged to apply the updates listed in OpenSSL Security Advisory 20060928.

Systems Affected

VendorStatusDate NotifiedDate Updated
Debian GNU/LinuxVulnerable4-Oct-2006
FreeBSD, Inc.Vulnerable29-Sep-2006
OpenSSLVulnerable28-Sep-2006
Red Hat, Inc.Vulnerable29-Sep-2006
UbuntuVulnerable28-Sep-2006

References


http://www.openssl.org/news/secadv_20060928.txt
http://www.openssl.org/
http://secunia.com/advisories/23131/
http://secunia.com/advisories/22544/
http://secunia.com/advisories/22385/
http://secunia.com/advisories/22671/
http://secunia.com/advisories/23155/
http://secunia.com/advisories/23340/
http://secunia.com/advisories/22094/
http://secunia.com/advisories/22259/
http://www.f-secure.com/security/fsc-2006-6.shtml
http://secunia.com/advisories/23280/
http://secunia.com/advisories/23309/
http://secunia.com/advisories/23351/
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102668-1

Credit

This vulnerability was reported by the OpenSSL development team in OpenSSL Security Advisory 20060928. The OpenSSL team, in turn, acknowledge Dr. S. N. Henson of Open Network Security and NISCC for funding the ASN.1 test suite project that lead to the discovery of this issue.

This document was written by Ryan Giobbi.

Other Information

Date Public:2006-09-28
Date First Published:2006-09-28
Date Last Updated:2007-02-09
CERT Advisory: 
CVE-ID(s):CVE-2006-2937
NVD-ID(s):CVE-2006-2937
US-CERT Technical Alerts: 
Metric:0.28
Document Revision:31

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader