CVE-2006-4790
Published Sep 14, 2006
Last updated 7 years ago
Overview
- Description
- verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Social media
- Hype score
- Not currently trending
Vendor comments
- Red HatRed Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:gnu:gnutls:1.0.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8856E1B1-8007-42E5-82EF-4700D4DEEDDA" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.0.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A9CF40D3-CE03-4C2A-8EEF-EB5989291806" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.0.19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC60D4CC-922C-4941-A400-0CBEAC7F31D1" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.0.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "754A0D19-A17A-4007-8355-497D14CFCBF9" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.0.21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8140DBE1-8116-4051-9A57-07535586E0AF" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.0.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "56D2DF7F-DCDD-486D-B906-F9DDE3A1DB70" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.0.23:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1CC840D-AD01-4EE2-8652-06742A6286BA" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.0.24:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "84224A82-6D58-4000-A449-20C1632DAE85" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.0.25:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A466931C-769A-4A28-B072-10930CE655E6" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.1.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "10F621DC-7967-4D97-A562-02E7033C89C2" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.1.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "776E5481-399F-45BC-AD20-A18508B03916" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.1.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "63D7F972-9128-4A4D-8508-B38CE2F155E9" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.1.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5D56873-E8C5-4E4B-BB85-6DCF6526B453" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.1.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54FE4766-32D0-491E-8C71-5B998C468142" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.1.19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F980857-2364-466A-8366-BD017D242222" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.1.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4CDCF1F0-5A78-48FF-B4B0-303AE2420F6A" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.1.21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A2E649D-5C45-4412-927B-E3EDCE07587C" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.1.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "066175C2-6E96-4BAE-B1A6-B23D25547FAC" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.1.23:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "869D3010-67AE-44D0-BB8F-D9C410AEA1D8" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "052B40C1-C29B-4189-9A45-DAE873AB716D" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "02F71E61-7455-4E10-B9D8-2B7FDDFB10F6" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5E05A9A1-6B7A-43FB-A9B8-41B68CA5FDCD" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1FB08FD9-9AB8-4015-A8BE-FD9F7EBAC6DA" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B588AAE0-8C3F-47C7-812F-8C97BD8795E5" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBB9154B-4254-4F33-8DB2-5B96E2DA4931" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64D9C191-6A57-40BB-BDD1-6B1A6BBAB51E" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2EA79D1-2EA8-4040-A5B5-C93EE937945A" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "61D05BC3-1315-4AC7-884D-41459272C94B" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.8.1a1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2901E522-6F54-4FA5-BF22-463A9D6B53D8" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "738F29DA-9741-4BA5-B370-417443A3AC2E" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52173492-1031-4AA4-A600-6210581059D3" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.2.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BB636C36-2884-4F66-B68A-4494AEAF90C3" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "777A16E4-A1F5-48DC-9BF0-CD9F0DCF8B55" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC4231BD-201D-4B10-9E35-B9EEFC714F6A" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C9200C3-0F46-4238-918B-38D95BF11547" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "024A9511-7CB4-4681-8429-0FE7FC34DF1A" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34CEF5ED-87A5-44B2-8A4A-9896957C057B" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B84A4F5-CED7-4633-913F-BE8235F68616" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "97564ABD-F9CE-4B3C-978A-1622DE3E4924" }, { "criteria": "cpe:2.3:a:gnu:gnutls:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3DB6EC88-DCE0-439B-89CD-18229965849B" } ], "operator": "OR" } ] } ]