Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-4339

Опубликовано: 05 сент. 2006
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

РелизСтатусПримечание
dapper

released

0.9.8a-7ubuntu0.3
devel

released

0.9.8b-2ubuntu2
edgy

released

0.9.8b-2ubuntu2
feisty

released

0.9.8b-2ubuntu2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

0.9.7g-5ubuntu1.1
devel

released

0.9.7k-3
edgy

released

0.9.7k-3
feisty

released

0.9.7k-3
upstream

needs-triage

Показывать по

EPSS

Процентиль: 91%
0.04854
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.1
redhat
почти 20 лет назад

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

nvd
почти 20 лет назад

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

debian
почти 20 лет назад

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, wh ...

github
больше 4 лет назад

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

fstec
почти 20 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

EPSS

Процентиль: 91%
0.04854
Низкий

4.3 Medium

CVSS2