CVE Vulnerabilities

CVE-2006-4343

NULL Pointer Dereference

Published: Sep 28, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl0.9.7 (including)0.9.7 (including)
OpensslOpenssl0.9.7a (including)0.9.7a (including)
OpensslOpenssl0.9.7b (including)0.9.7b (including)
OpensslOpenssl0.9.7c (including)0.9.7c (including)
OpensslOpenssl0.9.7d (including)0.9.7d (including)
OpensslOpenssl0.9.7e (including)0.9.7e (including)
OpensslOpenssl0.9.7f (including)0.9.7f (including)
OpensslOpenssl0.9.7g (including)0.9.7g (including)
OpensslOpenssl0.9.7h (including)0.9.7h (including)
OpensslOpenssl0.9.7i (including)0.9.7i (including)
OpensslOpenssl0.9.7j (including)0.9.7j (including)
OpensslOpenssl0.9.7k (including)0.9.7k (including)
OpensslOpenssl0.9.8 (including)0.9.8 (including)
OpensslOpenssl0.9.8a (including)0.9.8a (including)
OpensslOpenssl0.9.8b (including)0.9.8b (including)
OpensslOpenssl0.9.8c (including)0.9.8c (including)
Red Hat Enterprise Linux 2.1RedHatopenssl-0:0.9.6b-46*
Red Hat Enterprise Linux 2.1RedHatopenssl095a-0:0.9.5a-32*
Red Hat Enterprise Linux 2.1RedHatopenssl096-0:0.9.6-32*
Red Hat Enterprise Linux 3RedHatopenssl-0:0.9.7a-33.21*
Red Hat Enterprise Linux 3RedHatopenssl096b-0:0.9.6b-16.46*
Red Hat Enterprise Linux 4RedHatopenssl-0:0.9.7a-43.14*
Red Hat Enterprise Linux 4RedHatopenssl096b-0:0.9.6b-22.46*
Red Hat Network Satellite Server v 4.2RedHatrhn-solaris-bootstrap-0:5.0.2-3*
Red Hat Network Satellite Server v 4.2RedHatrhn_solaris_bootstrap_5_0_2_3-0:1-0*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn-solaris-bootstrap-0:5.0.2-3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn_solaris_bootstrap_5_0_2_3-0:1-0*
Red Hat Network Satellite Server v 5.0RedHatrhn-solaris-bootstrap-0:5.0.2-3*
Red Hat Network Satellite Server v 5.0RedHatrhn_solaris_bootstrap_5_0_2_3-0:1-0*
Red Hat Network Satellite Server v 5.1RedHatrhn-solaris-bootstrap-0:5.1.1-3*
Red Hat Network Satellite Server v 5.1RedHatrhn_solaris_bootstrap_5_1_1_3-0:1-0*
OpensslUbuntudapper*
OpensslUbuntudevel*
OpensslUbuntuedgy*
OpensslUbuntufeisty*
Openssl097Ubuntudapper*
Openssl097Ubuntudevel*
Openssl097Ubuntuedgy*
Openssl097Ubuntufeisty*

Potential Mitigations

References