CVE-2006-2937

Publication date 28 September 2006

Last updated 24 July 2024


Ubuntu priority

OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition.

Status

Package Ubuntu Release Status
openssl 7.04 feisty
Fixed 0.9.8b-2ubuntu2
6.10 edgy
Fixed 0.9.8b-2ubuntu2
6.06 LTS dapper
Fixed 0.9.8a-7ubuntu0.3
openssl097 7.04 feisty
Fixed 0.9.7k-3
6.10 edgy
Fixed 0.9.7k-3
6.06 LTS dapper
Fixed 0.9.7g-5ubuntu1.1

References

Related Ubuntu Security Notices (USN)

    • USN-353-1
    • openssl vulnerabilities
    • 29 September 2006

Other references