← Vulnerability feed

Vulnerability record · CVE-2006-3738 · published 28 September 2006

CVE-2006-3738: OpenSSL SSL_get_shared_ciphers buffer overflow via long cipher list

OOpenssl · Openssl

OpenSSL versions before 0.9.7l and 0.9.8d contain a buffer overflow in the SSL_get_shared_ciphers function, triggered by a long list of ciphers. The flaw has unspecified impact and remote attack vectors, but a successful overflow could allow code execution or denial of service in processes using the affected OpenSSL library.

10.0 CVSS 2.0 High EPSS 49% · top 1.2% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
250References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10 with remote, unauthenticated, low-complexity attack and complete impact, combined with high EPSS probability, warrants immediate remediation.

What it is

OpenSSL versions before 0.9.7l and 0.9.8d contain a buffer overflow in the SSL_get_shared_ciphers function, triggered by a long list of ciphers. The flaw has unspecified impact and remote attack vectors, but a successful overflow could allow code execution or denial of service in processes using the affected OpenSSL library.

Impact

An attacker could potentially execute arbitrary code or cause a denial of service in applications that call SSL_get_shared_ciphers with attacker-influenced cipher lists. The exact impact is not specified in the record, but the CVSS vector indicates complete loss of confidentiality, integrity, and availability.

Attack surface

The vulnerability is remotely reachable over the network (AV:N) with no authentication required (Au:N) and low attack complexity (AC:L). Exploitation requires the ability to influence the cipher list passed to SSL_get_shared_ciphers, which may occur during SSL/TLS handshake processing in affected applications.

Exploitation

The CVE is not listed in CISA KEV, but EPSS indicates a 30-day exploitation probability of 0.49273 (98.8th percentile), suggesting a high likelihood of exploitation activity. No public exploit references are tagged in the provided data.

What to do

  • Upgrade OpenSSL to version 0.9.7l, 0.9.8d, or later as specified in vendor advisories.
  • Apply patches from operating system or software vendors that bundle OpenSSL (e.g., Apple, HP, NetBSD, OpenBSD, SGI).
  • If immediate patching is not possible, restrict network access to services using affected OpenSSL versions and monitor for anomalous TLS handshake traffic.
  • Review applications that call SSL_get_shared_ciphers and validate or limit the size of cipher lists accepted from untrusted sources.
  • Monitor vendor advisories for updated patches and reapply as necessary.

Detection

  • Monitor network traffic for unusually long or malformed cipher lists during TLS handshakes that could trigger the overflow.
  • Check application and system logs for crashes or abnormal termination in processes linked to OpenSSL, especially during SSL/TLS negotiation.
  • Use vulnerability scanning tools to identify hosts running OpenSSL versions prior to 0.9.7l or 0.9.8d.
  • Deploy intrusion detection signatures that flag attempts to exploit known OpenSSL buffer overflows in SSL_get_shared_ciphers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.asc
ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc
http://docs.info.apple.com/article.html?artnum=304829
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771
http://issues.rpath.com/browse/RPL-613
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540
http://kolab.org/security/kolab-vendor-notice-11.txt Patch
http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049715.html Patch
http://marc.info/?l=bugtraq&m=130497311408250&w=2
http://openbsd.org/errata.html#openssl2 Patch
http://openvpn.net/changelog.html Patch
http://secunia.com/advisories/22094 PatchVendor Advisory
http://secunia.com/advisories/22116 PatchVendor Advisory
http://secunia.com/advisories/22130 PatchVendor Advisory
http://secunia.com/advisories/22165 PatchVendor Advisory
http://secunia.com/advisories/22166 PatchVendor Advisory
http://secunia.com/advisories/22172 PatchVendor Advisory
http://secunia.com/advisories/22186 PatchVendor Advisory
http://secunia.com/advisories/22193 PatchVendor Advisory
http://secunia.com/advisories/22207 PatchVendor Advisory
http://secunia.com/advisories/22212 PatchVendor Advisory
http://secunia.com/advisories/22216 PatchVendor Advisory
http://secunia.com/advisories/22220 PatchVendor Advisory
http://secunia.com/advisories/22240 PatchVendor Advisory
http://secunia.com/advisories/22259 PatchVendor Advisory
http://secunia.com/advisories/22260 PatchVendor Advisory
http://secunia.com/advisories/22284 PatchVendor Advisory
http://secunia.com/advisories/22298
http://secunia.com/advisories/22330 PatchVendor Advisory
http://secunia.com/advisories/22385
http://secunia.com/advisories/22460
http://secunia.com/advisories/22487
http://secunia.com/advisories/22500
http://secunia.com/advisories/22544
http://secunia.com/advisories/22626
http://secunia.com/advisories/22633
http://secunia.com/advisories/22654
http://secunia.com/advisories/22758

Track CVE-2006-3738 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2009-3245Openssl improper input validation vulnerabilityOpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) c…EPSS 6.5%9.8CVE-2026-63073Openssl vulnerabilityIssue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_da…EPSS 1.2%9.8CVE-2026-31789Openssl out-of-bounds write vulnerabilityIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact…EPSS 0.33%9.8CVE-2022-2274OpenSSL 3.0.4 RSA AVX512IFMA memory corruptionOpenSSL 3.0.4 introduced a bug in the RSA implementation for X86_64 CPUs supporting AVX512IFMA instructions, causing 2048-bit private key operations …EPSS 46%analysed9.8CVE-2021-3711OpenSSL SM2 decryption buffer overflowOpenSSL's SM2 decryption code miscalculates the output buffer size needed by EVP_PKEY_decrypt(), so the first sizing call can return a value smaller …EPSS 88%analysed9.8CVE-2016-6309OpenSSL 1.1.0a statem use-after-free on realloc in TLS session handlingOpenSSL 1.1.0a's statem/statem.c fails to account for memory-block movement after a realloc call, leaving a dangling pointer that can be used after f…EPSS 70%analysed9.8CVE-2016-6303Nodejs node.js out-of-bounds write vulnerabilityInteger overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (…EPSS 32%

Source: NIST National Vulnerability Database (record CVE-2006-3738), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.