Vulnerability Name:

CVE-2006-3127 (CCN-31536)

Assigned:2006-06-13
Published:2006-06-13
Updated:2011-03-07
Summary:Memory leak in Network Security Services (NSS) 3.11, as used in Sun Java Enterprise System 2003Q4 through 2005Q1 and Java System Directory Server 5.2, allows remote attackers to cause a denial of service (memory consumption) by performing a large number of RSA cryptographic operations.
CVSS v3 Severity:7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2006-3127

Source: CCN
Type: SA25048
Sun Java System Directory Server NSS Denial of Service

Source: SECUNIA
Type: Vendor Advisory
25048

Source: CCN
Type: SECTRACK ID: 1016294
Java Enterprise System (JES) Network Security Services (NSS) Memory Leak Lets Remote Users Deny Service

Source: SECTRACK
Type: UNKNOWN
1016294

Source: CCN
Type: Sun Alert ID: 102461
Systems With Sun Java Enterprise System Installed May Hang Due to a Memory Leak in the Network Security Services (NSS) Software

Source: SUNALERT
Type: Vendor Advisory
102461

Source: CCN
Type: Sun Alert ID: 102896
Directory Server May Hang Due to a Memory Leak in the Network Security Services (NSS) Software

Source: SUNALERT
Type: UNKNOWN
102896

Source: CCN
Type: ASA-2007-173
Directory Server May Hang Due to a Memory Leak in the Network Security Services (NSS) Software (Sun 102896)

Source: CCN
Type: OSVDB ID: 27621
Network Security Services (NSS) RSA Cryptographic Operation Saturation DoS

Source: FEDORA
Type: UNKNOWN
FEDORA-2006-728

Source: BID
Type: UNKNOWN
18604

Source: CCN
Type: BID-18604
Mozilla Network Security Services Library Remote Denial of Service Vulnerability

Source: BID
Type: UNKNOWN
20846

Source: CCN
Type: BID-20846
RETIRED: Sun Java System Network Security Services Remote Denial of Service Vulnerability

Source: VUPEN
Type: Vendor Advisory
ADV-2007-1573

Source: XF
Type: UNKNOWN
jes-nss-dos(31536)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sun:java_enterprise_system:2003q4:*:*:*:*:*:*:*
  • OR cpe:/a:sun:java_enterprise_system:2004q2:*:*:*:*:*:*:*
  • OR cpe:/a:sun:java_enterprise_system:2005q1:*:*:*:*:*:*:*
  • OR cpe:/a:sun:java_system_directory_server:5.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:sun:java_enterprise_system:2003q4:*:*:*:*:*:*:*
  • OR cpe:/a:sun:java_enterprise_system:2004q2:*:*:*:*:*:*:*
  • OR cpe:/a:sun:java_system_directory_server:5.2:*:*:*:*:*:*:*
  • OR cpe:/a:sun:java_enterprise_system:2005q1:*:*:*:*:*:*:*
  • AND
  • cpe:/o:sun:solaris:8::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::sparc:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sun java enterprise system 2003q4
    sun java enterprise system 2004q2
    sun java enterprise system 2005q1
    sun java system directory server 5.2
    sun java enterprise system 2003q4
    sun java enterprise system 2004q2
    sun java system directory server 5.2
    sun java enterprise system 2005q1
    sun solaris 8
    sun solaris 8
    sun solaris 9
    sun solaris 10
    sun solaris 10
    sun solaris 9