Return to CVE list

CVE-2006-4790

5.0
Medium

CVE-2006-4790

secalert@redhat.com
Deferred

Description

verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.

Exploits

No known exploits found for this CVE.

Search Exploit-DB

References

af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21937
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21942
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21973
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22049
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22080
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22084
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22097
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22226
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22992
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25762
af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-200609-15.xml
af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1016844
af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2006/dsa-1182
af854a3a-2127-422b-91ae-364da2661108
http://www.gnu.org/software/gnutls/security.html
af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/20027
af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-348-1
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3635
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3899
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/2289