SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#547300

OpenSSL SSL_get_shared_ciphers() vulnerable to buffer overflow

Overview

A buffer overflow vulnerability in an OpenSSL library function could allow a remote attacker to execute code on an affected system.

I. Description

The OpenSSL toolkit implements the Secure Sockets Layer (SSL versions 2 and 3) and Transport Layer Security (TLS version 1) protocols as well as a general purpose cryptographic library. The OpenSSL library includes a utility function, SSL_get_shared_ciphers(), to generate human readable strings from the list of shared ciphers supported on an SSL connection. A buffer overflow exists in this function's handling of the length of the list of shared ciphers. Any application using this function could expose the vulnerability, allowing an attacker to execute code with the privileges of that application. Note that although successful exploitation is believed to be difficult, it is still possible in some situations.

II. Impact

An attacker with the ability to supply a specially crafted list of ciphers could execute code in the context of an application using the vulnerable function.

III. Solution

Upgrade or apply a patch from the vendor

Patches have been released to address this issue. Please see the Systems Affected section of this document for more information.

Users or redistributors who compile OpenSSL from the original source code distribution are encouraged to review OpenSSL Security Advisory [28th September 2006] and upgrade to the appropriate fixed version of the software.

Systems Affected

VendorStatusDate NotifiedDate Updated
3com, Inc.Unknown15-Sep-2006
Aladdin Knowledge SystemsUnknown15-Sep-2006
AlcatelUnknown15-Sep-2006
America Online, Inc.Unknown15-Sep-2006
Apache-SSLUnknown15-Sep-2006
Apache HTTP Server ProjectUnknown15-Sep-2006
Apple Computer, Inc.Unknown15-Sep-2006
Aruba Networks, Inc.Unknown15-Sep-2006
AttachmateWRQ, Inc.Unknown15-Sep-2006
AT&TUnknown15-Sep-2006
Avaya, Inc.Unknown15-Sep-2006
Avici Systems, Inc.Unknown15-Sep-2006
Borderware TechnologiesUnknown15-Sep-2006
CerticomUnknown15-Sep-2006
Charlotte's Web NetworksUnknown15-Sep-2006
Check Point Software TechnologiesUnknown15-Sep-2006
Chiaro Networks, Inc.Unknown15-Sep-2006
Cisco Systems, Inc.Unknown15-Sep-2006
ClavisterUnknown15-Sep-2006
Command Software SystemsUnknown15-Sep-2006
Computer AssociatesUnknown15-Sep-2006
Conectiva Inc.Unknown15-Sep-2006
Covalent TechnologiesUnknown15-Sep-2006
Cray Inc.Unknown15-Sep-2006
CryptlibUnknown15-Sep-2006
Crypto++ LibraryUnknown15-Sep-2006
CyberSoft, Inc.Unknown15-Sep-2006
D-Link Systems, Inc.Unknown15-Sep-2006
Data Connection, Ltd.Unknown15-Sep-2006
DataFellowsUnknown15-Sep-2006
Debian GNU/LinuxVulnerable2-Oct-2006
EMC, Inc. (formerly Data General Corporation)Unknown15-Sep-2006
Engarde Secure LinuxUnknown15-Sep-2006
EricssonUnknown15-Sep-2006
eSoft, Inc.Unknown15-Sep-2006
Extreme NetworksUnknown15-Sep-2006
F-PROT by FRISK Software InternationalUnknown15-Sep-2006
F-Secure CorporationUnknown15-Sep-2006
F5 Networks, Inc.Vulnerable21-Sep-2006
Fedora ProjectUnknown15-Sep-2006
Finjan SoftwareUnknown15-Sep-2006
Force10 Networks, Inc.Unknown15-Sep-2006
Fortinet, Inc.Unknown15-Sep-2006
Foundry Networks, Inc.Unknown15-Sep-2006
FreeBSD, Inc.Vulnerable28-Sep-2006
FujitsuNot Vulnerable29-Sep-2006
Gentoo LinuxUnknown15-Sep-2006
GFI Software, Inc.Unknown15-Sep-2006
Global Technology AssociatesNot Vulnerable18-Sep-2006
Hewlett-Packard CompanyUnknown15-Sep-2006
HitachiUnknown15-Sep-2006
HyperchipUnknown15-Sep-2006
IAIK Java GroupUnknown15-Sep-2006
IBM CorporationUnknown15-Sep-2006
IBM Corporation (zseries)Unknown15-Sep-2006
IBM eServerUnknown15-Sep-2006
Immunix Communications, Inc.Unknown15-Sep-2006
Ingrian Networks, Inc.Unknown15-Sep-2006
Intel CorporationUnknown15-Sep-2006
Internet Security Systems, Inc.Unknown15-Sep-2006
IntotoUnknown15-Sep-2006
IP FilterUnknown15-Sep-2006
Juniper Networks, Inc.Unknown15-Sep-2006
Linksys (A division of Cisco Systems)Unknown15-Sep-2006
Lotus SoftwareUnknown15-Sep-2006
lshUnknown15-Sep-2006
Lucent TechnologiesUnknown15-Sep-2006
Luminous NetworksUnknown15-Sep-2006
Mandriva, Inc.Unknown15-Sep-2006
MessageLabsUnknown15-Sep-2006
Microsoft CorporationUnknown15-Sep-2006
Microsoft Internet ExplorerUnknown15-Sep-2006
Mirapoint, Inc.Unknown15-Sep-2006
mod_sslUnknown15-Sep-2006
MontaVista Software, Inc.Unknown15-Sep-2006
Mozilla - Network Security ServicesUnknown15-Sep-2006
Mozilla, Inc.Unknown15-Sep-2006
Multinet (owned Process Software Corporation)Unknown15-Sep-2006
Multitech, Inc.Unknown15-Sep-2006
MySQL ABUnknown15-Sep-2006
NEC CorporationUnknown15-Sep-2006
NetBSDUnknown15-Sep-2006
netfilterUnknown15-Sep-2006
Netscape NSSUnknown15-Sep-2006
Network Appliance, Inc.Unknown15-Sep-2006
NextHop Technologies, Inc.Unknown15-Sep-2006
NokiaUnknown15-Sep-2006
Nortel Networks, Inc.Unknown15-Sep-2006
Novell, Inc.Unknown15-Sep-2006
OpenBSDUnknown15-Sep-2006
OpenPKGVulnerable2-Oct-2006
OpenSSLVulnerable28-Sep-2006
Openwall GNU/*/LinuxUnknown15-Sep-2006
Oracle CorporationVulnerable17-Jan-2007
Proland Software, Inc.Unknown15-Sep-2006
QNX, Software Systems, Inc.Unknown15-Sep-2006
Red Hat, Inc.Vulnerable2-Oct-2006
Redback Networks, Inc.Unknown15-Sep-2006
Riverstone Networks, Inc.Unknown15-Sep-2006
rPathVulnerable2-Oct-2006
RSA Security, Inc.Unknown15-Sep-2006
Secure Computing Network Security DivisionUnknown15-Sep-2006
Secureworx, Inc.Unknown15-Sep-2006
Sendmail ConsortiumUnknown15-Sep-2006
Sendmail, Inc.Unknown22-Sep-2006
Silicon Graphics, Inc.Unknown15-Sep-2006
Slackware Linux Inc.Vulnerable2-Oct-2006
Sony CorporationUnknown15-Sep-2006
Sophos, Inc.Unknown15-Sep-2006
SpyrusUnknown15-Sep-2006
StonesoftVulnerable29-Sep-2006
StunnelUnknown15-Sep-2006
Sun Microsystems, Inc.Unknown15-Sep-2006
SUSE LinuxVulnerable2-Oct-2006
Symantec, Inc.Unknown15-Sep-2006
The SCO GroupUnknown15-Sep-2006
TrendmicroUnknown15-Sep-2006
Trustix Secure LinuxVulnerable2-Oct-2006
TurbolinuxUnknown15-Sep-2006
UbuntuVulnerable28-Sep-2006
UnisysUnknown15-Sep-2006
Watchguard Technologies, Inc.Unknown15-Sep-2006
Wietse VenemaUnknown15-Sep-2006
Wind River Systems, Inc.Unknown15-Sep-2006
ZyXELUnknown15-Sep-2006

References


http://www.openssl.org/news/secadv_20060928.txt
http://jvn.jp/cert/JVNVU%23547300/index.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049715.html
https://issues.rpath.com/browse/RPL-613
http://www.openssl.org/news/secadv_20060928.txt
http://kolab.org/security/kolab-vendor-notice-11.txt
http://openvpn.net/changelog.html
http://www.serv-u.com/releasenotes/
http://openbsd.org/errata.html#openssl2
http://www.securityfocus.com/bid/20249
http://securitytracker.com/id?1016943
http://secunia.com/advisories/22130
http://secunia.com/advisories/22094
http://secunia.com/advisories/22165
http://secunia.com/advisories/22186
http://secunia.com/advisories/22193
http://secunia.com/advisories/22207
http://secunia.com/advisories/22259
http://secunia.com/advisories/22260
http://secunia.com/advisories/22166
http://secunia.com/advisories/22172
http://secunia.com/advisories/22212
http://secunia.com/advisories/22240
http://secunia.com/advisories/22216
http://secunia.com/advisories/22116
http://secunia.com/advisories/22220
http://secunia.com/advisories/22284
http://secunia.com/advisories/22330
http://xforce.iss.net/xforce/xfdb/29237
http://secunia.com/advisories/23280/
http://secunia.com/advisories/23309/
http://www.securityfocus.com/bid/22083
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102668-1

Credit

Thanks to Tavis Ormandy and Will Drewry of the Google Security Team for reporting this vulnerability.

This document was written by Chad R Dougherty.

Other Information

Date Public:2006-09-28
Date First Published:2006-09-28
Date Last Updated:2007-02-09
CERT Advisory: 
CVE-ID(s):CVE-2006-3738
NVD-ID(s):CVE-2006-3738
US-CERT Technical Alerts: 
Metric:2.53
Document Revision:37

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader