Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-4339

Опубликовано: 05 сент. 2006
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

РелизСтатусПримечание
dapper

released

0.9.8a-7ubuntu0.3
devel

released

0.9.8b-2ubuntu2
edgy

released

0.9.8b-2ubuntu2
feisty

released

0.9.8b-2ubuntu2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

0.9.7g-5ubuntu1.1
devel

released

0.9.7k-3
edgy

released

0.9.7k-3
feisty

released

0.9.7k-3
upstream

needs-triage

Показывать по

EPSS

Процентиль: 92%
0.09411
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
почти 19 лет назад

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

nvd
почти 19 лет назад

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

debian
почти 19 лет назад

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, wh ...

github
больше 3 лет назад

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

fstec
почти 19 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

EPSS

Процентиль: 92%
0.09411
Низкий

4.3 Medium

CVSS2