Unrated severityNVD Advisory· Published Sep 28, 2006· Updated Apr 23, 2026
CVE-2006-3738
CVE-2006-3738
Description
Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.
Affected products
16cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7b:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7c:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7d:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7e:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7f:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7g:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7h:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7i:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7j:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.7k:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
125- kolab.org/security/kolab-vendor-notice-11.txtnvdPatch
- lists.grok.org.uk/pipermail/full-disclosure/2006-September/049715.htmlnvdPatch
- openbsd.org/errata.htmlnvdPatch
- openvpn.net/changelog.htmlnvdPatch
- secunia.com/advisories/22094nvdPatchVendor Advisory
- secunia.com/advisories/22116nvdPatchVendor Advisory
- secunia.com/advisories/22130nvdPatchVendor Advisory
- secunia.com/advisories/22165nvdPatchVendor Advisory
- secunia.com/advisories/22166nvdPatchVendor Advisory
- secunia.com/advisories/22172nvdPatchVendor Advisory
- secunia.com/advisories/22186nvdPatchVendor Advisory
- secunia.com/advisories/22193nvdPatchVendor Advisory
- secunia.com/advisories/22207nvdPatchVendor Advisory
- secunia.com/advisories/22212nvdPatchVendor Advisory
- secunia.com/advisories/22216nvdPatchVendor Advisory
- secunia.com/advisories/22220nvdPatchVendor Advisory
- secunia.com/advisories/22240nvdPatchVendor Advisory
- secunia.com/advisories/22259nvdPatchVendor Advisory
- secunia.com/advisories/22260nvdPatchVendor Advisory
- secunia.com/advisories/22284nvdPatchVendor Advisory
- secunia.com/advisories/22330nvdPatchVendor Advisory
- security.freebsd.org/advisories/FreeBSD-SA-06:23.openssl.ascnvdPatchVendor Advisory
- securitytracker.com/idnvdPatch
- slackware.com/security/viewer.phpnvdPatch
- sunsolve.sun.com/search/document.donvdPatch
- www.debian.org/security/2006/dsa-1185nvdPatch
- www.debian.org/security/2006/dsa-1195nvdPatchVendor Advisory
- www.novell.com/linux/security/advisories/2006_24_sr.htmlnvdPatchVendor Advisory
- www.novell.com/linux/security/advisories/2006_58_openssl.htmlnvdPatchVendor Advisory
- www.openpkg.org/security/advisories/OpenPKG-SA-2006.021-openssl.htmlnvdPatchVendor Advisory
- www.osvdb.org/29262nvdPatch
- www.redhat.com/support/errata/RHSA-2006-0695.htmlnvdPatch
- www.securityfocus.com/bid/20249nvdPatch
- www.trustix.org/errata/2006/0054nvdPatch
- www.ubuntu.com/usn/usn-353-1nvdPatch
- www.kb.cert.org/vuls/id/547300nvdUS Government Resource
- www.us-cert.gov/cas/techalerts/TA06-333A.htmlnvdUS Government Resource
- ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.ascnvd
- patches.sgi.com/support/free/security/advisories/20061001-01-P.ascnvd
- docs.info.apple.com/article.htmlnvd
- h20000.www2.hp.com/bizsupport/TechSupport/Document.jspnvd
- issues.rpath.com/browse/RPL-613nvd
- itrc.hp.com/service/cki/docDisplay.donvd
- itrc.hp.com/service/cki/docDisplay.donvd
- lists.apple.com/archives/security-announce/2006/Nov/msg00001.htmlnvd
- marc.infonvd
- secunia.com/advisories/22298nvd
- secunia.com/advisories/22385nvd
- secunia.com/advisories/22460nvd
- secunia.com/advisories/22487nvd
- secunia.com/advisories/22500nvd
- secunia.com/advisories/22544nvd
- secunia.com/advisories/22626nvd
- secunia.com/advisories/22633nvd
- secunia.com/advisories/22654nvd
- secunia.com/advisories/22758nvd
- secunia.com/advisories/22772nvd
- secunia.com/advisories/22791nvd
- secunia.com/advisories/22799nvd
- secunia.com/advisories/23038nvd
- secunia.com/advisories/23155nvd
- secunia.com/advisories/23280nvd
- secunia.com/advisories/23309nvd
- secunia.com/advisories/23340nvd
- secunia.com/advisories/23680nvd
- secunia.com/advisories/23794nvd
- secunia.com/advisories/23915nvd
- secunia.com/advisories/24930nvd
- secunia.com/advisories/24950nvd
- secunia.com/advisories/25889nvd
- secunia.com/advisories/26329nvd
- secunia.com/advisories/30124nvd
- secunia.com/advisories/30161nvd
- secunia.com/advisories/31492nvd
- security.gentoo.org/glsa/glsa-200610-11.xmlnvd
- securitytracker.com/idnvd
- sourceforge.net/project/shownotes.phpnvd
- sunsolve.sun.com/search/document.donvd
- sunsolve.sun.com/search/document.donvd
- support.avaya.com/elmodocs2/security/ASA-2006-220.htmnvd
- support.avaya.com/elmodocs2/security/ASA-2006-260.htmnvd
- www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_response09186a008077af1b.htmlnvd
- www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtmlnvd
- www.gentoo.org/security/en/glsa/glsa-200612-11.xmlnvd
- www.gentoo.org/security/en/glsa/glsa-200805-07.xmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.openssl.org/news/secadv_20060928.txtnvd
- www.oracle.com/technetwork/topics/security/cpujan2007-101493.htmlnvd
- www.redhat.com/support/errata/RHSA-2008-0629.htmlnvd
- www.securityfocus.com/archive/1/447318/100/0/threadednvd
- www.securityfocus.com/archive/1/447393/100/0/threadednvd
- www.securityfocus.com/archive/1/456546/100/200/threadednvd
- www.securityfocus.com/archive/1/470460/100/0/threadednvd
- www.securityfocus.com/bid/22083nvd
- www.serv-u.com/releasenotes/nvd
- www.vmware.com/support/esx2/doc/esx-202-200612-patch.htmlnvd
- www.vmware.com/support/esx21/doc/esx-213-200612-patch.htmlnvd
- www.vmware.com/support/esx25/doc/esx-253-200612-patch.htmlnvd
- www.vmware.com/support/esx25/doc/esx-254-200612-patch.htmlnvd
- www.vmware.com/support/vi3/doc/esx-3069097-patch.htmlnvd
- www.vmware.com/support/vi3/doc/esx-9986131-patch.htmlnvd
- www.vupen.com/english/advisories/2006/3820nvd
- www.vupen.com/english/advisories/2006/3860nvd
- www.vupen.com/english/advisories/2006/3869nvd
- www.vupen.com/english/advisories/2006/3902nvd
- www.vupen.com/english/advisories/2006/3936nvd
- www.vupen.com/english/advisories/2006/4036nvd
- www.vupen.com/english/advisories/2006/4264nvd
- www.vupen.com/english/advisories/2006/4314nvd
- www.vupen.com/english/advisories/2006/4401nvd
- www.vupen.com/english/advisories/2006/4417nvd
- www.vupen.com/english/advisories/2006/4443nvd
- www.vupen.com/english/advisories/2006/4750nvd
- www.vupen.com/english/advisories/2007/0343nvd
- www.vupen.com/english/advisories/2007/1401nvd
- www.vupen.com/english/advisories/2007/2315nvd
- www.vupen.com/english/advisories/2007/2783nvd
- www.xerox.com/downloads/usa/en/c/cert_ESSNetwork_XRX07001_v1.pdfnvd
- www130.nortelnetworks.com/go/main.jspnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/29237nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4256nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9370nvd
- www2.itrc.hp.com/service/cki/docDisplay.donvd
News mentions
0No linked articles in our index yet.