CVE-2006-2937
openssl
EPSS 5.1%
Description
OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition.
How to fix CVE-2006-2937
To remediate CVE-2006-2937, upgrade the affected package to a fixed version below.
- Debian/openssl—upgrade to 0.9.8c-2 or later
- Debian/openssl—upgrade to 0.9.7e-3sarge4 or later
Is CVE-2006-2937 being exploited?
Moderate — EPSS is 5.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 0.9.8c-2
- from 0, < 0.9.7e-3sarge4