CVE-2006-4340
Summary
| CVE | CVE-2006-4340 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-15 18:07:00 UTC |
| Updated | 2023-11-07 01:59:00 UTC |
| Description | Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Network Security Services | All | All | All | All |
| Application | Mozilla | Seamonkey | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gentoo update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Sun Solaris update for Mozilla - Advisories - Secunia | SECUNIA | secunia.com | |
| Red Hat update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Avaya Products Firefox Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| [#RPL-640] update to firefox 1.5.0.7 and thunderbird 1.5.0.7 for critical security fixes - rPath JIRA | CONFIRM | issues.rpath.com | |
| Ubuntu update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Debian update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| Debian -- Security Information -- DSA-1210-1 mozilla-firefox | DEBIAN | www.debian.org | |
| Debian -- Security Information -- DSA-1192-1 mozilla | DEBIAN | www.debian.org | |
| usn/usn-350-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| MFSA 2006-60: RSA Signature Forgery | CONFIRM | www.mozilla.org | |
| Mandriva update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| rPath updates for firefox and thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Security Announcement | SUSE | www.novell.com | |
| Gentoo update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| Red Hat update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Security Announcement | SUSE | www.novell.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| HP-UX update for firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| SecurityTracker.com Archives - Mozilla Firefox Certificate Signatures Can Be Forged | SECTRACK | securitytracker.com | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Gentoo Linux Documentation -- Mozilla Firefox: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| Gentoo Linux Documentation -- Mozilla Network Security Service (NSS): RSA signature forgery | GENTOO | www.gentoo.org | |
| Ubuntu update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Debian update for mozilla - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Debian update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| usn/usn-354-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| Mozilla Thunderbird Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Bleichenbacher's RSA signature forgery based on implementation error | MLIST | www.imc.org | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| ASA-2006-224 (RHSA-2006-0675) | CONFIRM | support.avaya.com | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Ubuntu update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Gentoo Linux Documentation -- Mozilla Thunderbird: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| Debian -- Security Information -- DSA-1191-1 mozilla-thunderbird | DEBIAN | www.us.debian.org | |
| SUSE update for openssl/mozilla-nss - Advisories - Secunia | SECUNIA | secunia.com | |
| Ubuntu update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Mozilla SeaMonkey Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Avaya CMS Sun Solaris X Display Manager Security Issue - Advisories - Secunia | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Gentoo update for nss - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Mozilla Thunderbird Certificate Signatures Can Be Forged | SECTRACK | securitytracker.com | |
| usn/usn-352-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| Network Security Services (NSS) Signature Forgery Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Netscape Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| 20060901-01-P | SGI | patches.sgi.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Mozilla Firefox Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| usn/usn-351-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| SUSE updates for MozillaFirefox, MozillaThunderbird, and seamonkey - Advisories - Secunia | SECUNIA | secunia.com | |
| Ubuntu update for mozilla - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Vendor Advisory |
| #102648: Security Vulnerability in RSA Signature Verification Impacting Multiple SUN Products | SUNALERT | sunsolve.sun.com | |
| usn/usn-361-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| #102781: RSA Signature Forgery Issues in Mozilla 1.7 for Solaris 8, 9 and 10 | SUNALERT | sunsolve.sun.com | |
| MFSA 2006-66: RSA Signature Forgery (variant) | MISC | www.mozilla.org | |
| SecurityTracker.com Archives - Mozilla Seamonkey Certificate Signatures Can Be Forged | SECTRACK | securitytracker.com | |
| Matasano Chargen » Many RSA Signatures May Be Forgeable In OpenSSL and Elsewhere | MISC | www.matasano.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| US-CERT Technical Cyber Security Alert TA06-312A -- Mozilla Updates for Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| IT Resource Center - login / register | HP | www1.itrc.hp.com | |
| ASA-2006-250 (SUN 102606, 102636, 102640, 102648, 102651, 102652, 102655, 102657) | CONFIRM | support.avaya.com | |
| Sun Solaris RSA Signature Forgery Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Mandriva update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.