Return to CVE list

CVE-2006-4339

4.3
Medium

CVE-2006-4339

secalert@redhat.com
Deferred

Description

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

Exploits

No known exploits found for this CVE.

Search Exploit-DB

References

secalert@redhat.com
http://www.osvdb.org/28549
af854a3a-2127-422b-91ae-364da2661108
http://dev2dev.bea.com/pub/advisory/238
af854a3a-2127-422b-91ae-364da2661108
http://docs.info.apple.com/article.html?artnum=304829
af854a3a-2127-422b-91ae-364da2661108
http://docs.info.apple.com/article.html?artnum=307177
af854a3a-2127-422b-91ae-364da2661108
http://jvn.jp/en/jp/JVN51615542/index.html
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=130497311408250&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=130497311408250&w=2
af854a3a-2127-422b-91ae-364da2661108
http://openvpn.net/changelog.html
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21709
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21767
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21776
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21778
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21785
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21791
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21812
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21823
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21846
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21852
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21870
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21873
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21906
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21927
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21930
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21982
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22036
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22044
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22066
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22161
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22226
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22232
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22259
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22260
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22284
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22325
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22446
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22509
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22513
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22523
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22545
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22585
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22671
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22689
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22711
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22733
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22758
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22799
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22932
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22934
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22936
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22937
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22938
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22939
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22940
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22948
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22949
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23155
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23455
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23680
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23794
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23841
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/23915
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24099
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24930
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24950
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25284
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25399
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25649
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26329
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26893
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/28115
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/31492
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/38567
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/38568
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/41818
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/60799
af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-200609-05.xml
af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-200609-18.xml
af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1016791
af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1017522
af854a3a-2127-422b-91ae-364da2661108
http://support.attachmate.com/techdocs/2127.html
af854a3a-2127-422b-91ae-364da2661108
http://support.attachmate.com/techdocs/2128.html
af854a3a-2127-422b-91ae-364da2661108
http://support.attachmate.com/techdocs/2137.html
af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2006/dsa-1174
af854a3a-2127-422b-91ae-364da2661108
http://www.kb.cert.org/vuls/id/845620
af854a3a-2127-422b-91ae-364da2661108
http://www.openbsd.org/errata.html
af854a3a-2127-422b-91ae-364da2661108
http://www.openssl.org/news/secadv_20060905.txt
af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/28549
af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/19849
af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/22083
af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/28276
af854a3a-2127-422b-91ae-364da2661108
http://www.serv-u.com/releasenotes/
af854a3a-2127-422b-91ae-364da2661108
http://www.sybase.com/detail?id=1047991
af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-339-1
af854a3a-2127-422b-91ae-364da2661108
http://www.us-cert.gov/cas/techalerts/TA06-333A.html
af854a3a-2127-422b-91ae-364da2661108
http://www.us.debian.org/security/2006/dsa-1173
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3453
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3566
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3730
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3748
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3793
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3899
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3936
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4205
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4206
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4207
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4216
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4327
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4329
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4366
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4417
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4586
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4744
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/4750
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/5146
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/0254
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/0343
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/1401
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/1815
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/1945
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/2163
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/2315
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/2783
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/4224
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2010/0366
af854a3a-2127-422b-91ae-364da2661108
https://issues.rpath.com/browse/RPL-1633
af854a3a-2127-422b-91ae-364da2661108
https://issues.rpath.com/browse/RPL-616