CVE-2006-5462
Summary
| CVE | CVE-2006-5462 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-11-08 21:07:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340. |
Risk And Classification
Primary CVSS: v2.0 6.4 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5 | beta1 | All | All |
| Application | Mozilla | Firefox | 1.5 | beta2 | All | All |
| Application | Mozilla | Firefox | 1.5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.4 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.6 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.7 | All | All | All |
| Application | Mozilla | Network Security Services | 3.11.3 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | alpha | All |
| Application | Mozilla | Seamonkey | 1.0 | All | dev | All |
| Application | Mozilla | Seamonkey | 1.0 | beta | All | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.3 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.5 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5 | beta2 | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.3 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.4 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.6 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian update for mozilla-thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Ubuntu update for mozilla-thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Sun Solaris update for Mozilla - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Mozilla Firefox and SeaMonkey Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Mandriva update for mozilla-thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| HP-UX update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo update for seamonkey - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- Mozilla Thunderbird: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| US-CERT Vulnerability Note VU#335392 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Patch, US Government Resource |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Debian -- Security Information -- DSA-1225-2 mozilla-firefox | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| 356215 – FF1507 RSA signature forgery: unchecked padding length (CVE-2006-5462) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Patch |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| usn/usn-381-1 - Ubuntu: Linux for human beings | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Mozilla Thunderbird Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Ubuntu update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo update for mozilla-firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityTracker.com Archives - Mozilla Firefox RSA Signatures Can Be Forged | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Avaya Messaging Storage Server Firefox Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Netscape Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityTracker.com Archives - Mozilla Seamonkey RSA Signatures Can Be Forged | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Debian -- Security Information -- DSA-1224-1 mozilla | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Gentoo Linux Documentation -- Mozilla Firefox: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| usn/usn-382-1 - Ubuntu: Linux for human beings | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Gentoo Linux Documentation -- SeaMonkey: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| US-CERT Technical Cyber Security Alert TA06-312A -- Mozilla Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Patch, US Government Resource |
| SecurityTracker.com Archives - Mozilla Thunderbird RSA Signatures Can Be Forged | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| MFSA 2006-60: RSA Signature Forgery | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Patch |
| SUSE update for MozillaFirefox, MozillaThunderbird, and seamonkey - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| #102781: RSA Signature Forgery Issues in Mozilla 1.7 for Solaris 8, 9 and 10 | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Gentoo update for mozilla-thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IT Resource Center - login / register | af854a3a-2127-422b-91ae-364da2661108 | www1.itrc.hp.com | |
| Debian update for mozilla-firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat update for seamonkey - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| MFSA 2006-66: RSA Signature Forgery (variant) | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Patch |
| Red Hat update for thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| ASA-2006-246 (RHSA-2006-0733) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| Debian update for mozilla - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| patches.sgi.com/support/free/security/advisories/20061101-01-P | af854a3a-2127-422b-91ae-364da2661108 | patches.sgi.com | |
| Mandriva update for mozilla-firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1227-1 mozilla-thunderbird | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.