Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-5201


Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.


Published

2006-10-10T04:06:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:N/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

4.9

Impact Score

4.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sun nss * Yes
Application sun secure_global_desktop * Yes
Application sun staroffice * Yes
Operating System sun solaris 9.0 Yes
Operating System sun solaris 10.0 Yes
Operating System sun sunos 5.8 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jdk 1.5.0 Yes
Application sun jre 1.3.1 Yes
Application sun jre 1.3.1_2 Yes
Application sun jre 1.3.1_03 Yes
Application sun jre 1.3.1_04 Yes
Application sun jre 1.3.1_05 Yes
Application sun jre 1.3.1_06 Yes
Application sun jre 1.3.1_07 Yes
Application sun jre 1.3.1_08 Yes
Application sun jre 1.3.1_09 Yes
Application sun jre 1.3.1_10 Yes
Application sun jre 1.3.1_11 Yes
Application sun jre 1.3.1_12 Yes
Application sun jre 1.3.1_13 Yes
Application sun jre 1.3.1_14 Yes
Application sun jre 1.3.1_15 Yes
Application sun jre 1.3.1_16 Yes
Application sun jre 1.3.1_17 Yes
Application sun jre 1.3.1_18 Yes
Application sun jre 1.3.1_19 Yes
Application sun jre 1.4.2 Yes
Application sun jre 1.4.2_1 Yes
Application sun jre 1.4.2_2 Yes
Application sun jre 1.4.2_3 Yes
Application sun jre 1.4.2_4 Yes
Application sun jre 1.4.2_5 Yes
Application sun jre 1.4.2_6 Yes
Application sun jre 1.4.2_7 Yes
Application sun jre 1.4.2_8 Yes
Application sun jre 1.4.2_9 Yes
Application sun jre 1.4.2_10 Yes
Application sun jre 1.4.2_11 Yes
Application sun jre 1.4.2_12 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun jre 1.5.0 Yes
Application sun sdk 1.3.1 Yes
Application sun sdk 1.3.1_01 Yes
Application sun sdk 1.3.1_01a Yes
Application sun sdk 1.3.1_02 Yes
Application sun sdk 1.3.1_03 Yes
Application sun sdk 1.3.1_04 Yes
Application sun sdk 1.3.1_05 Yes
Application sun sdk 1.3.1_06 Yes
Application sun sdk 1.3.1_07 Yes
Application sun sdk 1.3.1_08 Yes
Application sun sdk 1.3.1_09 Yes
Application sun sdk 1.3.1_10 Yes
Application sun sdk 1.3.1_11 Yes
Application sun sdk 1.3.1_12 Yes
Application sun sdk 1.3.1_13 Yes
Application sun sdk 1.3.1_14 Yes
Application sun sdk 1.3.1_15 Yes
Application sun sdk 1.3.1_16 Yes
Application sun sdk 1.3.1_17 Yes
Application sun sdk 1.3.1_18 Yes
Application sun sdk 1.3.1_19 Yes
Application sun sdk 1.4.2 Yes
Application sun sdk 1.4.2_1 Yes
Application sun sdk 1.4.2_2 Yes
Application sun sdk 1.4.2_3 Yes
Application sun sdk 1.4.2_4 Yes
Application sun sdk 1.4.2_5 Yes
Application sun sdk 1.4.2_6 Yes
Application sun sdk 1.4.2_7 Yes
Application sun sdk 1.4.2_8 Yes
Application sun sdk 1.4.2_9 Yes
Application sun sdk 1.4.2_10 Yes
Application sun sdk 1.4.2_11 Yes
Application sun sdk 1.4.2_12 Yes
Application sun jsse 1.0.3 Yes
Application sun jsse 1.0.3_01 Yes
Application sun jsse 1.0.3_02 Yes
Application sun jsse 1.0.3_03 Yes

References