Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2005-2946

Опубликовано: 16 сент. 2005
Источник: debian
EPSS Низкий

Описание

The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensslfixed0.9.8-1package

Примечания

  • MD5 is still good enough for most applications, second preimage attacks

  • haven't been presented yet

EPSS

Процентиль: 40%
0.00177
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 20 лет назад

The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

CVSS3: 7.5
nvd
почти 20 лет назад

The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

CVSS3: 7.5
github
больше 3 лет назад

The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

EPSS

Процентиль: 40%
0.00177
Низкий