Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2005-2946

Опубликовано: 16 сент. 2005
Источник: debian
EPSS Низкий

Описание

The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensslfixed0.9.8-1package

Примечания

  • MD5 is still good enough for most applications, second preimage attacks

  • haven't been presented yet

EPSS

Процентиль: 41%
0.0019
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 20 лет назад

The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

CVSS3: 7.5
nvd
больше 20 лет назад

The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

CVSS3: 7.5
github
почти 4 года назад

The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

EPSS

Процентиль: 41%
0.0019
Низкий