CVE-2006-3127

Sun Java Enterprise System 2003Q4-2005Q1 - Denial of Service via RSA Cryptographic Operations

Title source: llm
STIX 2.1

Description

Memory leak in Network Security Services (NSS) 3.11, as used in Sun Java Enterprise System 2003Q4 through 2005Q1 and Java System Directory Server 5.2, allows remote attackers to cause a denial of service (memory consumption) by performing a large number of RSA cryptographic operations.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18604
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102461-1
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1573
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016294
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25048
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102896-1
Vendor Advisory vendor-advisory x_refsource_fedora
http://www.redhat.com/archives/fedora-package-announce/2006-June/msg00155.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20846

Scores

EPSS 0.0205
EPSS Percentile 84.1%

Details

CWE
CWE-399
Status published
Products (4)
sun/java_enterprise_system 2003q4
sun/java_enterprise_system 2004q2
sun/java_enterprise_system 2005q1
sun/java_system_directory_server 5.2
Published Jun 21, 2006
Tracked Since Feb 18, 2026