Description

The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.

INFO

Published Date :

Sept. 28, 2006, 6:07 p.m.

Last Modified :

Oct. 17, 2018, 9:36 p.m.

Remotely Exploitable :

Yes !

Impact Score :

2.9

Exploitability Score :

8.6
Public PoC/Exploit Available at Github

CVE-2006-4343 has a 1 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2006-4343 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Canonical ubuntu_linux
1 Debian debian_linux
1 Openssl openssl
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2006-4343.

URL Resource
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.asc Third Party Advisory
ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc Third Party Advisory
http://docs.info.apple.com/article.html?artnum=304829 Third Party Advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771 Broken Link
http://issues.rpath.com/browse/RPL-613 Broken Link
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100 Broken Link
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540 Broken Link
http://kolab.org/security/kolab-vendor-notice-11.txt Broken Link
http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html Mailing List Third Party Advisory
http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049715.html Mailing List Third Party Advisory
http://lists.vmware.com/pipermail/security-announce/2008/000008.html Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=130497311408250&w=2 Mailing List Third Party Advisory
http://openbsd.org/errata.html#openssl2 Third Party Advisory
http://openvpn.net/changelog.html Third Party Advisory
http://secunia.com/advisories/22094 Third Party Advisory
http://secunia.com/advisories/22116 Third Party Advisory
http://secunia.com/advisories/22130 Third Party Advisory
http://secunia.com/advisories/22165 Third Party Advisory
http://secunia.com/advisories/22166 Third Party Advisory
http://secunia.com/advisories/22172 Third Party Advisory
http://secunia.com/advisories/22186 Third Party Advisory
http://secunia.com/advisories/22193 Third Party Advisory
http://secunia.com/advisories/22207 Third Party Advisory
http://secunia.com/advisories/22212 Third Party Advisory
http://secunia.com/advisories/22216 Third Party Advisory
http://secunia.com/advisories/22220 Third Party Advisory
http://secunia.com/advisories/22240 Third Party Advisory
http://secunia.com/advisories/22259 Third Party Advisory
http://secunia.com/advisories/22260 Third Party Advisory
http://secunia.com/advisories/22284 Third Party Advisory
http://secunia.com/advisories/22298 Third Party Advisory
http://secunia.com/advisories/22330 Third Party Advisory
http://secunia.com/advisories/22385 Third Party Advisory
http://secunia.com/advisories/22460 Third Party Advisory
http://secunia.com/advisories/22487 Third Party Advisory
http://secunia.com/advisories/22500 Third Party Advisory
http://secunia.com/advisories/22544 Third Party Advisory
http://secunia.com/advisories/22626 Third Party Advisory
http://secunia.com/advisories/22758 Third Party Advisory
http://secunia.com/advisories/22772 Third Party Advisory
http://secunia.com/advisories/22791 Third Party Advisory
http://secunia.com/advisories/22799 Third Party Advisory
http://secunia.com/advisories/23038 Third Party Advisory
http://secunia.com/advisories/23155 Third Party Advisory
http://secunia.com/advisories/23280 Third Party Advisory
http://secunia.com/advisories/23309 Third Party Advisory
http://secunia.com/advisories/23340 Third Party Advisory
http://secunia.com/advisories/23680 Third Party Advisory
http://secunia.com/advisories/23794 Third Party Advisory
http://secunia.com/advisories/23915 Third Party Advisory
http://secunia.com/advisories/24950 Third Party Advisory
http://secunia.com/advisories/25420 Third Party Advisory
http://secunia.com/advisories/25889 Third Party Advisory
http://secunia.com/advisories/26329 Third Party Advisory
http://secunia.com/advisories/30124 Third Party Advisory
http://secunia.com/advisories/31492 Third Party Advisory
http://security.freebsd.org/advisories/FreeBSD-SA-06:23.openssl.asc Third Party Advisory
http://security.gentoo.org/glsa/glsa-200610-11.xml Third Party Advisory
http://securitytracker.com/id?1016943 Third Party Advisory VDB Entry
http://securitytracker.com/id?1017522 Third Party Advisory VDB Entry
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.676946 Mailing List Third Party Advisory
http://sourceforge.net/project/shownotes.php?release_id=461863&group_id=69227 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102668-1 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102711-1 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201531-1 Broken Link
http://support.avaya.com/elmodocs2/security/ASA-2006-220.htm Third Party Advisory
http://support.avaya.com/elmodocs2/security/ASA-2006-260.htm Third Party Advisory
http://www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_response09186a008077af1b.html Third Party Advisory
http://www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtml Third Party Advisory
http://www.debian.org/security/2006/dsa-1185 Third Party Advisory
http://www.debian.org/security/2006/dsa-1195 Third Party Advisory
http://www.gentoo.org/security/en/glsa/glsa-200612-11.xml Third Party Advisory
http://www.ingate.com/relnote-452.php Broken Link
http://www.kb.cert.org/vuls/id/386964 Patch Third Party Advisory US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2006:172 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:177 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:178 Broken Link
http://www.novell.com/linux/security/advisories/2006_24_sr.html Broken Link
http://www.novell.com/linux/security/advisories/2006_58_openssl.html Broken Link
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.021-openssl.html Third Party Advisory
http://www.openssl.org/news/secadv_20060928.txt Patch Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html Third Party Advisory
http://www.osvdb.org/29263 Broken Link
http://www.redhat.com/support/errata/RHSA-2006-0695.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0629.html Third Party Advisory
http://www.securityfocus.com/archive/1/447318/100/0/threaded
http://www.securityfocus.com/archive/1/447393/100/0/threaded
http://www.securityfocus.com/archive/1/456546/100/200/threaded
http://www.securityfocus.com/archive/1/489739/100/0/threaded
http://www.securityfocus.com/bid/20246 Patch Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/22083 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/28276 Third Party Advisory VDB Entry
http://www.serv-u.com/releasenotes/ Third Party Advisory
http://www.trustix.org/errata/2006/0054 Broken Link
http://www.ubuntu.com/usn/usn-353-1 Third Party Advisory
http://www.us-cert.gov/cas/techalerts/TA06-333A.html Third Party Advisory US Government Resource
http://www.vmware.com/security/advisories/VMSA-2008-0005.html Third Party Advisory
http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html Third Party Advisory
http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html Third Party Advisory
http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html Third Party Advisory
http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html Third Party Advisory
http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html Third Party Advisory
http://www.vmware.com/support/player/doc/releasenotes_player.html Third Party Advisory
http://www.vmware.com/support/player2/doc/releasenotes_player2.html Third Party Advisory
http://www.vmware.com/support/server/doc/releasenotes_server.html Third Party Advisory
http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html Third Party Advisory
http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html Third Party Advisory
http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html Third Party Advisory
http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html Third Party Advisory
http://www.vupen.com/english/advisories/2006/3820 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2006/3860 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2006/3869 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2006/3902 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2006/3936 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2006/4036 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2006/4264 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2006/4401 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2006/4417 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2006/4443 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2006/4750 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2007/0343 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2007/1401 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2007/1973 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2007/2783 Permissions Required Third Party Advisory
http://www.vupen.com/english/advisories/2008/0905/references Permissions Required Third Party Advisory
http://www.xerox.com/downloads/usa/en/c/cert_ESSNetwork_XRX07001_v1.pdf Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/29240 VDB Entry Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10207 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4356 Third Party Advisory
https://www.exploit-db.com/exploits/4773 Third Party Advisory VDB Entry
https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144 Broken Link

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

Updated: 3 weeks, 6 days ago
5 stars 0 fork 0 watcher
Born at : Feb. 23, 2023, 5:42 a.m. This repo has been linked 455 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2006-4343 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2006-4343 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • CVE Modified by [email protected]

    Oct. 17, 2018

    Action Type Old Value New Value
    Removed Reference http://www.securityfocus.com/archive/1/archive/1/489739/100/0/threaded [Third Party Advisory, VDB Entry]
    Removed Reference http://www.securityfocus.com/archive/1/archive/1/447393/100/0/threaded [Third Party Advisory, VDB Entry]
    Removed Reference http://www.securityfocus.com/archive/1/archive/1/456546/100/200/threaded [Third Party Advisory, VDB Entry]
    Removed Reference http://www.securityfocus.com/archive/1/archive/1/447318/100/0/threaded [Third Party Advisory, VDB Entry]
    Added Reference http://www.securityfocus.com/archive/1/489739/100/0/threaded [No Types Assigned]
    Added Reference http://www.securityfocus.com/archive/1/456546/100/200/threaded [No Types Assigned]
    Added Reference http://www.securityfocus.com/archive/1/447393/100/0/threaded [No Types Assigned]
    Added Reference http://www.securityfocus.com/archive/1/447318/100/0/threaded [No Types Assigned]
  • Modified Analysis by [email protected]

    Oct. 17, 2018

    Action Type Old Value New Value
    Changed Reference Type http://www.vupen.com/english/advisories/2006/4401 No Types Assigned http://www.vupen.com/english/advisories/2006/4401 Permissions Required, Third Party Advisory
    Changed Reference Type http://www.redhat.com/support/errata/RHSA-2006-0695.html Vendor Advisory http://www.redhat.com/support/errata/RHSA-2006-0695.html Third Party Advisory
    Changed Reference Type http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html No Types Assigned http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html Mailing List, Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/23915 No Types Assigned http://secunia.com/advisories/23915 Third Party Advisory
    Changed Reference Type http://www.securityfocus.com/archive/1/archive/1/489739/100/0/threaded No Types Assigned http://www.securityfocus.com/archive/1/archive/1/489739/100/0/threaded Third Party Advisory, VDB Entry
    Changed Reference Type http://secunia.com/advisories/22544 Vendor Advisory http://secunia.com/advisories/22544 Third Party Advisory
    Changed Reference Type http://www.ubuntu.com/usn/usn-353-1 No Types Assigned http://www.ubuntu.com/usn/usn-353-1 Third Party Advisory
    Changed Reference Type http://sunsolve.sun.com/search/document.do?assetkey=1-66-201531-1 No Types Assigned http://sunsolve.sun.com/search/document.do?assetkey=1-66-201531-1 Broken Link
    Changed Reference Type http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html No Types Assigned http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html Third Party Advisory
    Changed Reference Type http://issues.rpath.com/browse/RPL-613 No Types Assigned http://issues.rpath.com/browse/RPL-613 Broken Link
    Changed Reference Type http://secunia.com/advisories/22260 Vendor Advisory http://secunia.com/advisories/22260 Third Party Advisory
    Changed Reference Type http://security.gentoo.org/glsa/glsa-200610-11.xml No Types Assigned http://security.gentoo.org/glsa/glsa-200610-11.xml Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22385 Vendor Advisory http://secunia.com/advisories/22385 Third Party Advisory
    Changed Reference Type http://www.osvdb.org/29263 No Types Assigned http://www.osvdb.org/29263 Broken Link
    Changed Reference Type http://www.vupen.com/english/advisories/2006/3820 No Types Assigned http://www.vupen.com/english/advisories/2006/3820 Permissions Required, Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/31492 No Types Assigned http://secunia.com/advisories/31492 Third Party Advisory
    Changed Reference Type http://www.vupen.com/english/advisories/2006/4750 No Types Assigned http://www.vupen.com/english/advisories/2006/4750 Permissions Required, Third Party Advisory
    Changed Reference Type http://openbsd.org/errata.html#openssl2 No Types Assigned http://openbsd.org/errata.html#openssl2 Third Party Advisory
    Changed Reference Type http://www.securityfocus.com/archive/1/archive/1/447393/100/0/threaded No Types Assigned http://www.securityfocus.com/archive/1/archive/1/447393/100/0/threaded Third Party Advisory, VDB Entry
    Changed Reference Type http://secunia.com/advisories/22799 No Types Assigned http://secunia.com/advisories/22799 Third Party Advisory
    Changed Reference Type http://www.vupen.com/english/advisories/2007/1401 No Types Assigned http://www.vupen.com/english/advisories/2007/1401 Permissions Required, Third Party Advisory
    Changed Reference Type http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.676946 No Types Assigned http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.676946 Mailing List, Third Party Advisory
    Changed Reference Type http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html No Types Assigned http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html Third Party Advisory
    Changed Reference Type http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100 No Types Assigned http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100 Broken Link
    Changed Reference Type http://www.vupen.com/english/advisories/2006/3936 No Types Assigned http://www.vupen.com/english/advisories/2006/3936 Permissions Required, Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/25420 No Types Assigned http://secunia.com/advisories/25420 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22791 No Types Assigned http://secunia.com/advisories/22791 Third Party Advisory
    Changed Reference Type http://www.vmware.com/support/server/doc/releasenotes_server.html No Types Assigned http://www.vmware.com/support/server/doc/releasenotes_server.html Third Party Advisory
    Changed Reference Type http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html No Types Assigned http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html Third Party Advisory
    Changed Reference Type https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10207 No Types Assigned https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10207 Third Party Advisory
    Changed Reference Type http://lists.vmware.com/pipermail/security-announce/2008/000008.html No Types Assigned http://lists.vmware.com/pipermail/security-announce/2008/000008.html Mailing List, Third Party Advisory
    Changed Reference Type http://www.openssl.org/news/secadv_20060928.txt Patch http://www.openssl.org/news/secadv_20060928.txt Patch, Third Party Advisory
    Changed Reference Type https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144 No Types Assigned https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144 Broken Link
    Changed Reference Type http://secunia.com/advisories/22094 Vendor Advisory http://secunia.com/advisories/22094 Third Party Advisory
    Changed Reference Type http://www.vupen.com/english/advisories/2006/4264 No Types Assigned http://www.vupen.com/english/advisories/2006/4264 Permissions Required, Third Party Advisory
    Changed Reference Type http://docs.info.apple.com/article.html?artnum=304829 No Types Assigned http://docs.info.apple.com/article.html?artnum=304829 Third Party Advisory
    Changed Reference Type http://sunsolve.sun.com/search/document.do?assetkey=1-26-102711-1 No Types Assigned http://sunsolve.sun.com/search/document.do?assetkey=1-26-102711-1 Broken Link
    Changed Reference Type https://www.exploit-db.com/exploits/4773 No Types Assigned https://www.exploit-db.com/exploits/4773 Third Party Advisory, VDB Entry
    Changed Reference Type http://secunia.com/advisories/26329 No Types Assigned http://secunia.com/advisories/26329 Third Party Advisory
    Changed Reference Type http://www.novell.com/linux/security/advisories/2006_58_openssl.html No Types Assigned http://www.novell.com/linux/security/advisories/2006_58_openssl.html Broken Link
    Changed Reference Type http://www.ingate.com/relnote-452.php No Types Assigned http://www.ingate.com/relnote-452.php Broken Link
    Changed Reference Type http://www.mandriva.com/security/advisories?name=MDKSA-2006:172 No Types Assigned http://www.mandriva.com/security/advisories?name=MDKSA-2006:172 Third Party Advisory
    Changed Reference Type http://www.mandriva.com/security/advisories?name=MDKSA-2006:177 No Types Assigned http://www.mandriva.com/security/advisories?name=MDKSA-2006:177 Third Party Advisory
    Changed Reference Type http://www.mandriva.com/security/advisories?name=MDKSA-2006:178 No Types Assigned http://www.mandriva.com/security/advisories?name=MDKSA-2006:178 Broken Link
    Changed Reference Type http://secunia.com/advisories/22240 Vendor Advisory http://secunia.com/advisories/22240 Third Party Advisory
    Changed Reference Type http://www.vupen.com/english/advisories/2006/4417 No Types Assigned http://www.vupen.com/english/advisories/2006/4417 Permissions Required, Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22487 Vendor Advisory http://secunia.com/advisories/22487 Third Party Advisory
    Changed Reference Type http://support.avaya.com/elmodocs2/security/ASA-2006-260.htm No Types Assigned http://support.avaya.com/elmodocs2/security/ASA-2006-260.htm Third Party Advisory
    Changed Reference Type http://openvpn.net/changelog.html No Types Assigned http://openvpn.net/changelog.html Third Party Advisory
    Changed Reference Type http://www.vmware.com/support/player2/doc/releasenotes_player2.html No Types Assigned http://www.vmware.com/support/player2/doc/releasenotes_player2.html Third Party Advisory
    Changed Reference Type http://www.vupen.com/english/advisories/2008/0905/references No Types Assigned http://www.vupen.com/english/advisories/2008/0905/references Permissions Required, Third Party Advisory
    Changed Reference Type http://www.trustix.org/errata/2006/0054 No Types Assigned http://www.trustix.org/errata/2006/0054 Broken Link
    Changed Reference Type http://secunia.com/advisories/25889 No Types Assigned http://secunia.com/advisories/25889 Third Party Advisory
    Changed Reference Type http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html No Types Assigned http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22259 Vendor Advisory http://secunia.com/advisories/22259 Third Party Advisory
    Changed Reference Type http://www.securityfocus.com/bid/22083 No Types Assigned http://www.securityfocus.com/bid/22083 Third Party Advisory, VDB Entry
    Changed Reference Type http://secunia.com/advisories/22130 Vendor Advisory http://secunia.com/advisories/22130 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/23340 No Types Assigned http://secunia.com/advisories/23340 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/24950 No Types Assigned http://secunia.com/advisories/24950 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22772 No Types Assigned http://secunia.com/advisories/22772 Third Party Advisory
    Changed Reference Type http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html No Types Assigned http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html Third Party Advisory
    Changed Reference Type http://www.vupen.com/english/advisories/2006/4443 No Types Assigned http://www.vupen.com/english/advisories/2006/4443 Permissions Required, Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/23280 No Types Assigned http://secunia.com/advisories/23280 Third Party Advisory
    Changed Reference Type http://marc.info/?l=bugtraq&m=130497311408250&w=2 No Types Assigned http://marc.info/?l=bugtraq&m=130497311408250&w=2 Mailing List, Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22193 Vendor Advisory http://secunia.com/advisories/22193 Third Party Advisory
    Changed Reference Type http://securitytracker.com/id?1017522 No Types Assigned http://securitytracker.com/id?1017522 Third Party Advisory, VDB Entry
    Changed Reference Type http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html No Types Assigned http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22500 Vendor Advisory http://secunia.com/advisories/22500 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/23038 No Types Assigned http://secunia.com/advisories/23038 Third Party Advisory
    Changed Reference Type http://www.vupen.com/english/advisories/2007/1973 No Types Assigned http://www.vupen.com/english/advisories/2007/1973 Permissions Required, Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22626 Vendor Advisory http://secunia.com/advisories/22626 Third Party Advisory
    Changed Reference Type http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.021-openssl.html No Types Assigned http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.021-openssl.html Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22186 Vendor Advisory http://secunia.com/advisories/22186 Third Party Advisory
    Changed Reference Type http://www.debian.org/security/2006/dsa-1195 No Types Assigned http://www.debian.org/security/2006/dsa-1195 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22460 Vendor Advisory http://secunia.com/advisories/22460 Third Party Advisory
    Changed Reference Type http://support.avaya.com/elmodocs2/security/ASA-2006-220.htm No Types Assigned http://support.avaya.com/elmodocs2/security/ASA-2006-220.htm Third Party Advisory
    Changed Reference Type http://www.vupen.com/english/advisories/2006/3869 No Types Assigned http://www.vupen.com/english/advisories/2006/3869 Permissions Required, Third Party Advisory
    Changed Reference Type http://www.vupen.com/english/advisories/2006/3902 No Types Assigned http://www.vupen.com/english/advisories/2006/3902 Permissions Required, Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/23794 No Types Assigned http://secunia.com/advisories/23794 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22220 Vendor Advisory http://secunia.com/advisories/22220 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/23155 No Types Assigned http://secunia.com/advisories/23155 Third Party Advisory
    Changed Reference Type http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771 No Types Assigned http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771 Broken Link
    Changed Reference Type http://www.gentoo.org/security/en/glsa/glsa-200612-11.xml No Types Assigned http://www.gentoo.org/security/en/glsa/glsa-200612-11.xml Third Party Advisory
    Changed Reference Type http://www.vupen.com/english/advisories/2006/3860 No Types Assigned http://www.vupen.com/english/advisories/2006/3860 Permissions Required, Third Party Advisory
    Changed Reference Type http://www.vupen.com/english/advisories/2006/4036 No Types Assigned http://www.vupen.com/english/advisories/2006/4036 Permissions Required, Third Party Advisory
    Changed Reference Type http://www.securityfocus.com/bid/20246 Patch http://www.securityfocus.com/bid/20246 Patch, Third Party Advisory, VDB Entry
    Changed Reference Type http://sunsolve.sun.com/search/document.do?assetkey=1-26-102668-1 No Types Assigned http://sunsolve.sun.com/search/document.do?assetkey=1-26-102668-1 Broken Link
    Changed Reference Type http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html No Types Assigned http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html Third Party Advisory
    Changed Reference Type http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html No Types Assigned http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/30124 No Types Assigned http://secunia.com/advisories/30124 Third Party Advisory
    Changed Reference Type http://securitytracker.com/id?1016943 No Types Assigned http://securitytracker.com/id?1016943 Third Party Advisory, VDB Entry
    Changed Reference Type http://kolab.org/security/kolab-vendor-notice-11.txt No Types Assigned http://kolab.org/security/kolab-vendor-notice-11.txt Broken Link
    Changed Reference Type http://www.vupen.com/english/advisories/2007/2783 No Types Assigned http://www.vupen.com/english/advisories/2007/2783 Permissions Required, Third Party Advisory
    Changed Reference Type ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc No Types Assigned ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22116 Vendor Advisory http://secunia.com/advisories/22116 Third Party Advisory
    Changed Reference Type http://security.freebsd.org/advisories/FreeBSD-SA-06:23.openssl.asc No Types Assigned http://security.freebsd.org/advisories/FreeBSD-SA-06:23.openssl.asc Third Party Advisory
    Changed Reference Type http://www.us-cert.gov/cas/techalerts/TA06-333A.html US Government Resource http://www.us-cert.gov/cas/techalerts/TA06-333A.html Third Party Advisory, US Government Resource
    Changed Reference Type ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.asc No Types Assigned ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.asc Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22758 No Types Assigned http://secunia.com/advisories/22758 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/23680 No Types Assigned http://secunia.com/advisories/23680 Third Party Advisory
    Changed Reference Type http://www.securityfocus.com/archive/1/archive/1/456546/100/200/threaded No Types Assigned http://www.securityfocus.com/archive/1/archive/1/456546/100/200/threaded Third Party Advisory, VDB Entry
    Changed Reference Type http://www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_response09186a008077af1b.html No Types Assigned http://www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_response09186a008077af1b.html Third Party Advisory
    Changed Reference Type http://www.vmware.com/security/advisories/VMSA-2008-0005.html No Types Assigned http://www.vmware.com/security/advisories/VMSA-2008-0005.html Third Party Advisory
    Changed Reference Type http://www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtml No Types Assigned http://www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtml Third Party Advisory
    Changed Reference Type http://www.novell.com/linux/security/advisories/2006_24_sr.html No Types Assigned http://www.novell.com/linux/security/advisories/2006_24_sr.html Broken Link
    Changed Reference Type http://www.securityfocus.com/archive/1/archive/1/447318/100/0/threaded No Types Assigned http://www.securityfocus.com/archive/1/archive/1/447318/100/0/threaded Third Party Advisory, VDB Entry
    Changed Reference Type http://secunia.com/advisories/22207 Vendor Advisory http://secunia.com/advisories/22207 Third Party Advisory
    Changed Reference Type http://www.kb.cert.org/vuls/id/386964 Patch, US Government Resource http://www.kb.cert.org/vuls/id/386964 Patch, Third Party Advisory, US Government Resource
    Changed Reference Type http://sourceforge.net/project/shownotes.php?release_id=461863&group_id=69227 No Types Assigned http://sourceforge.net/project/shownotes.php?release_id=461863&group_id=69227 Broken Link
    Changed Reference Type http://secunia.com/advisories/22284 Vendor Advisory http://secunia.com/advisories/22284 Third Party Advisory
    Changed Reference Type http://www.securityfocus.com/bid/28276 No Types Assigned http://www.securityfocus.com/bid/28276 Third Party Advisory, VDB Entry
    Changed Reference Type https://exchange.xforce.ibmcloud.com/vulnerabilities/29240 No Types Assigned https://exchange.xforce.ibmcloud.com/vulnerabilities/29240 Third Party Advisory, VDB Entry
    Changed Reference Type http://secunia.com/advisories/22166 Vendor Advisory http://secunia.com/advisories/22166 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22165 Vendor Advisory http://secunia.com/advisories/22165 Third Party Advisory
    Changed Reference Type http://www.serv-u.com/releasenotes/ No Types Assigned http://www.serv-u.com/releasenotes/ Third Party Advisory
    Changed Reference Type http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html No Types Assigned http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html Third Party Advisory
    Changed Reference Type http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049715.html No Types Assigned http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049715.html Mailing List, Third Party Advisory
    Changed Reference Type http://www.vupen.com/english/advisories/2007/0343 No Types Assigned http://www.vupen.com/english/advisories/2007/0343 Permissions Required, Third Party Advisory
    Changed Reference Type http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540 No Types Assigned http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540 Broken Link
    Changed Reference Type http://secunia.com/advisories/22216 Vendor Advisory http://secunia.com/advisories/22216 Third Party Advisory
    Changed Reference Type https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4356 No Types Assigned https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4356 Third Party Advisory
    Changed Reference Type http://www.vmware.com/support/player/doc/releasenotes_player.html No Types Assigned http://www.vmware.com/support/player/doc/releasenotes_player.html Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/23309 No Types Assigned http://secunia.com/advisories/23309 Third Party Advisory
    Changed Reference Type http://www.xerox.com/downloads/usa/en/c/cert_ESSNetwork_XRX07001_v1.pdf No Types Assigned http://www.xerox.com/downloads/usa/en/c/cert_ESSNetwork_XRX07001_v1.pdf Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22172 Vendor Advisory http://secunia.com/advisories/22172 Third Party Advisory
    Changed Reference Type http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html No Types Assigned http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html Third Party Advisory
    Changed Reference Type http://www.debian.org/security/2006/dsa-1185 No Types Assigned http://www.debian.org/security/2006/dsa-1185 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22298 No Types Assigned http://secunia.com/advisories/22298 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22330 Vendor Advisory http://secunia.com/advisories/22330 Third Party Advisory
    Changed Reference Type http://secunia.com/advisories/22212 Vendor Advisory http://secunia.com/advisories/22212 Third Party Advisory
    Changed Reference Type http://www.redhat.com/support/errata/RHSA-2008-0629.html No Types Assigned http://www.redhat.com/support/errata/RHSA-2008-0629.html Third Party Advisory
    Removed CWE NVD-CWE-Other
    Added CWE CWE-476
    Changed CPE Configuration OR *cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7b:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7c:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7d:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7e:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7f:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7g:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7h:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7i:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7j:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions up to (including) 0.9.7k *cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions up to (including) 0.9.8c OR *cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7b:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7c:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7d:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7e:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7f:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7g:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7h:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7i:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7j:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.7k:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:* *cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*
    Added CPE Configuration OR *cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
    Added CPE Configuration OR *cpe:2.3:o:canonical:ubuntu_linux:5.04:*:*:*:*:*:*:* *cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:* *cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
  • CVE Modified by [email protected]

    Oct. 11, 2017

    Action Type Old Value New Value
    Removed Reference http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10207 [No Types Assigned]
    Removed Reference http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4356 [Tool Signature, US Government Resource]
    Removed Reference http://www.milw0rm.com/exploits/4773 [No Types Assigned]
    Added Reference https://www.exploit-db.com/exploits/4773 [No Types Assigned]
    Added Reference https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4356 [No Types Assigned]
    Added Reference https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10207 [No Types Assigned]
  • CVE Modified by [email protected]

    Jul. 20, 2017

    Action Type Old Value New Value
    Removed Reference http://xforce.iss.net/xforce/xfdb/29240 [No Types Assigned]
    Added Reference https://exchange.xforce.ibmcloud.com/vulnerabilities/29240 [No Types Assigned]
  • Initial Analysis by [email protected]

    Oct. 02, 2006

    Action Type Old Value New Value
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2006-4343 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2006-4343 weaknesses.

Exploit Prediction

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

0.94 }} -0.63%

score

0.83340

percentile

CVSS2 - Vulnerability Scoring System
Access Vector
Access Complexity
Authentication
Confidentiality
Integrity
Availability