{"api_version":"1","generated_at":"2026-07-23T11:36:20+00:00","cve":"CVE-2006-4340","urls":{"html":"https://cve.report/CVE-2006-4340","api":"https://cve.report/api/cve/CVE-2006-4340.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4340","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4340"},"summary":{"title":"CVE-2006-4340","description":"Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2006-09-15 18:07:00","updated_at":"2023-11-07 01:59:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"http://secunia.com/advisories/22274","name":"22274","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Gentoo update for mozilla-thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23883","name":"23883","refsource":"SECUNIA","tags":[],"title":"Sun Solaris update for Mozilla - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21916","name":"21916","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Red Hat update for thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22422","name":"22422","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Avaya Products Firefox Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://issues.rpath.com/browse/RPL-640","name":"https://issues.rpath.com/browse/RPL-640","refsource":"CONFIRM","tags":[],"title":"[#RPL-640] update to firefox 1.5.0.7 and thunderbird 1.5.0.7 for critical security fixes - rPath JIRA","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/22025","name":"22025","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Ubuntu update for firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22849","name":"22849","refsource":"SECUNIA","tags":[],"title":"Debian update for mozilla-firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2006/dsa-1210","name":"DSA-1210","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-1210-1 mozilla-firefox","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2006/dsa-1192","name":"DSA-1192","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-1192-1 mozilla","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-350-1","name":"USN-350-1","refsource":"UBUNTU","tags":[],"title":"usn/usn-350-1 - Ubuntu: Linux for human beings","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2006/mfsa2006-60.html","name":"http://www.mozilla.org/security/announce/2006/mfsa2006-60.html","refsource":"CONFIRM","tags":[],"title":"MFSA 2006-60: RSA Signature Forgery","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22001","name":"22001","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Mandriva update for mozilla-firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22036","name":"22036","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21950","name":"21950","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"rPath updates for firefox and thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2006_54_mozilla.html","name":"SUSE-SA:2006:054","refsource":"SUSE","tags":[],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/22195","name":"22195","refsource":"SECUNIA","tags":[],"title":"Gentoo update for mozilla-firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21949","name":"21949","refsource":"SECUNIA","tags":["Patch","Vendor Advisory"],"title":"Red Hat update for firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2006_55_ssl.html","name":"SUSE-SA:2006:055","refsource":"SUSE","tags":[],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2006-0676.html","name":"RHSA-2006:0676","refsource":"REDHAT","tags":["Patch","Vendor Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3899","name":"ADV-2006-3899","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22066","name":"22066","refsource":"SECUNIA","tags":[],"title":"HP-UX update for firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1016858","name":"1016858","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - Mozilla Firefox Certificate Signatures Can Be Forged","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/1198","name":"ADV-2007-1198","refsource":"VUPEN","tags":[],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30098","name":"mozilla-nss-security-bypass(30098)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-200609-19.xml","name":"GLSA-200609-19","refsource":"GENTOO","tags":[],"title":"Gentoo Linux Documentation\n--\n  Mozilla Firefox: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200610-06.xml","name":"GLSA-200610-06","refsource":"GENTOO","tags":[],"title":"Gentoo Linux Documentation\n--\n  Mozilla Network Security Service (NSS): RSA signature forgery","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22055","name":"22055","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Ubuntu update for mozilla-thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22299","name":"22299","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Debian update for mozilla - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22247","name":"22247","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Debian update for mozilla-thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11007","name":"oval:org.mitre.oval:def:11007","refsource":"OVAL","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-354-1","name":"USN-354-1","refsource":"UBUNTU","tags":[],"title":"usn/usn-354-1 - Ubuntu: Linux for human beings","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/21939","name":"21939","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Mozilla Thunderbird Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.imc.org/ietf-openpgp/mail-archive/msg14307.html","name":"[ietf-openpgp] 20060827 Bleichenbacher's RSA signature forgery based on implementation error","refsource":"MLIST","tags":[],"title":"Bleichenbacher's RSA signature forgery based on implementation error","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/446140/100/0/threaded","name":"20060915 rPSA-2006-0169-1 firefox thunderbird","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm","name":"http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm","refsource":"CONFIRM","tags":[],"title":"ASA-2006-224 (RHSA-2006-0675)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/0293","name":"ADV-2007-0293","refsource":"VUPEN","tags":[],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22074","name":"22074","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Ubuntu update for mozilla-thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0083","name":"ADV-2008-0083","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-200610-01.xml","name":"GLSA-200610-01","refsource":"GENTOO","tags":[],"title":"Gentoo Linux Documentation\n--\n  Mozilla Thunderbird: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us.debian.org/security/2006/dsa-1191","name":"DSA-1191","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-1191-1 mozilla-thunderbird","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/22044","name":"22044","refsource":"SECUNIA","tags":[],"title":"SUSE update for openssl/mozilla-nss - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22210","name":"22210","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Ubuntu update for firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21940","name":"21940","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Mozilla SeaMonkey Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22992","name":"22992","refsource":"SECUNIA","tags":[],"title":"Avaya CMS Sun Solaris X Display Manager Security Issue - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3748","name":"ADV-2006-3748","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21915","name":"21915","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Red Hat update for seamonkey - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22446","name":"22446","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Gentoo update for nss - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1016860","name":"1016860","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - Mozilla Thunderbird Certificate Signatures Can Be Forged","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-352-1","name":"USN-352-1","refsource":"UBUNTU","tags":[],"title":"usn/usn-352-1 - Ubuntu: Linux for human beings","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21903","name":"21903","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Network Security Services (NSS) Signature Forgery Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/24711","name":"24711","refsource":"SECUNIA","tags":[],"title":"Netscape Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc","name":"20060901-01-P","refsource":"SGI","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.vupen.com/english/advisories/2006/3617","name":"ADV-2006-3617","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21906","name":"21906","refsource":"SECUNIA","tags":["Patch","Vendor Advisory"],"title":"Mozilla Firefox Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-351-1","name":"USN-351-1","refsource":"UBUNTU","tags":[],"title":"usn/usn-351-1 - Ubuntu: Linux for human beings","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22056","name":"22056","refsource":"SECUNIA","tags":[],"title":"SUSE updates for MozillaFirefox, MozillaThunderbird, and seamonkey - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22342","name":"22342","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Ubuntu update for mozilla - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2006-0675.html","name":"RHSA-2006:0675","refsource":"REDHAT","tags":["Vendor Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1","name":"102648","refsource":"SUNALERT","tags":[],"title":"#102648: Security Vulnerability in RSA Signature Verification Impacting Multiple SUN Products","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-361-1","name":"USN-361-1","refsource":"UBUNTU","tags":[],"title":"usn/usn-361-1 - Ubuntu: Linux for human beings","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102781-1","name":"102781","refsource":"SUNALERT","tags":[],"title":"#102781: RSA Signature Forgery Issues in Mozilla 1.7 for Solaris 8, 9 and 10","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2006/mfsa2006-66.html","name":"http://www.mozilla.org/security/announce/2006/mfsa2006-66.html","refsource":"MISC","tags":[],"title":"MFSA 2006-66: RSA Signature Forgery (variant)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1016859","name":"1016859","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - Mozilla Seamonkey Certificate Signatures Can Be Forged","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/","name":"http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/","refsource":"MISC","tags":[],"title":"Matasano Chargen » Many RSA Signatures May Be Forgeable In OpenSSL and Elsewhere","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2006-0677.html","name":"RHSA-2006:0677","refsource":"REDHAT","tags":["Patch","Vendor Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3622","name":"ADV-2006-3622","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA06-312A.html","name":"TA06-312A","refsource":"CERT","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA06-312A -- Mozilla Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742","name":"SSRT061181","refsource":"HP","tags":[],"title":"IT Resource Center - login / register","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2006-250.htm","name":"http://support.avaya.com/elmodocs2/security/ASA-2006-250.htm","refsource":"CONFIRM","tags":[],"title":"ASA-2006-250 (SUN 102606, 102636, 102640, 102648, 102651, 102652,\r\n       102655, 102657)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22226","name":"22226","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Sun Solaris RSA Signature Forgery Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22088","name":"22088","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Mandriva update for mozilla-thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2006:168","name":"MDKSA-2006:168","refsource":"MANDRIVA","tags":[],"title":"Advisories - Mandriva Linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2006:169","name":"MDKSA-2006:169","refsource":"MANDRIVA","tags":[],"title":"Advisories - Mandriva Linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4340","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4340","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4340","vulnerable":"1","versionEndIncluding":"1.5.0.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4340","vulnerable":"1","versionEndIncluding":"3.11.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"network_security_services","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4340","vulnerable":"1","versionEndIncluding":"1.0.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"seamonkey","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4340","vulnerable":"1","versionEndIncluding":"1.5.0.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"thunderbird","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2006-4340","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_affected":"=","version_value":"n/a"}]}}]}}]}},"references":{"reference_data":[{"url":"http://secunia.com/advisories/22055","refsource":"MISC","name":"http://secunia.com/advisories/22055"},{"url":"http://secunia.com/advisories/22066","refsource":"MISC","name":"http://secunia.com/advisories/22066"},{"url":"http://secunia.com/advisories/22210","refsource":"MISC","name":"http://secunia.com/advisories/22210"},{"url":"http://secunia.com/advisories/22342","refsource":"MISC","name":"http://secunia.com/advisories/22342"},{"url":"http://www.ubuntu.com/usn/usn-350-1","refsource":"MISC","name":"http://www.ubuntu.com/usn/usn-350-1"},{"url":"http://www.ubuntu.com/usn/usn-354-1","refsource":"MISC","name":"http://www.ubuntu.com/usn/usn-354-1"},{"url":"http://www.ubuntu.com/usn/usn-361-1","refsource":"MISC","name":"http://www.ubuntu.com/usn/usn-361-1"},{"url":"http://www.vupen.com/english/advisories/2006/3748","refsource":"MISC","name":"http://www.vupen.com/english/advisories/2006/3748"},{"url":"http://www.vupen.com/english/advisories/2008/0083","refsource":"MISC","name":"http://www.vupen.com/english/advisories/2008/0083"},{"url":"ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc","refsource":"MISC","name":"ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc"},{"url":"http://secunia.com/advisories/21903","refsource":"MISC","name":"http://secunia.com/advisories/21903"},{"url":"http://secunia.com/advisories/21906","refsource":"MISC","name":"http://secunia.com/advisories/21906"},{"url":"http://secunia.com/advisories/21915","refsource":"MISC","name":"http://secunia.com/advisories/21915"},{"url":"http://secunia.com/advisories/21916","refsource":"MISC","name":"http://secunia.com/advisories/21916"},{"url":"http://secunia.com/advisories/21939","refsource":"MISC","name":"http://secunia.com/advisories/21939"},{"url":"http://secunia.com/advisories/21940","refsource":"MISC","name":"http://secunia.com/advisories/21940"},{"url":"http://secunia.com/advisories/21949","refsource":"MISC","name":"http://secunia.com/advisories/21949"},{"url":"http://secunia.com/advisories/21950","refsource":"MISC","name":"http://secunia.com/advisories/21950"},{"url":"http://secunia.com/advisories/22001","refsource":"MISC","name":"http://secunia.com/advisories/22001"},{"url":"http://secunia.com/advisories/22025","refsource":"MISC","name":"http://secunia.com/advisories/22025"},{"url":"http://secunia.com/advisories/22036","refsource":"MISC","name":"http://secunia.com/advisories/22036"},{"url":"http://secunia.com/advisories/22044","refsource":"MISC","name":"http://secunia.com/advisories/22044"},{"url":"http://secunia.com/advisories/22056","refsource":"MISC","name":"http://secunia.com/advisories/22056"},{"url":"http://secunia.com/advisories/22074","refsource":"MISC","name":"http://secunia.com/advisories/22074"},{"url":"http://secunia.com/advisories/22088","refsource":"MISC","name":"http://secunia.com/advisories/22088"},{"url":"http://secunia.com/advisories/22195","refsource":"MISC","name":"http://secunia.com/advisories/22195"},{"url":"http://secunia.com/advisories/22226","refsource":"MISC","name":"http://secunia.com/advisories/22226"},{"url":"http://secunia.com/advisories/22247","refsource":"MISC","name":"http://secunia.com/advisories/22247"},{"url":"http://secunia.com/advisories/22274","refsource":"MISC","name":"http://secunia.com/advisories/22274"},{"url":"http://secunia.com/advisories/22299","refsource":"MISC","name":"http://secunia.com/advisories/22299"},{"url":"http://secunia.com/advisories/22422","refsource":"MISC","name":"http://secunia.com/advisories/22422"},{"url":"http://secunia.com/advisories/22446","refsource":"MISC","name":"http://secunia.com/advisories/22446"},{"url":"http://secunia.com/advisories/22849","refsource":"MISC","name":"http://secunia.com/advisories/22849"},{"url":"http://secunia.com/advisories/22992","refsource":"MISC","name":"http://secunia.com/advisories/22992"},{"url":"http://secunia.com/advisories/23883","refsource":"MISC","name":"http://secunia.com/advisories/23883"},{"url":"http://secunia.com/advisories/24711","refsource":"MISC","name":"http://secunia.com/advisories/24711"},{"url":"http://security.gentoo.org/glsa/glsa-200609-19.xml","refsource":"MISC","name":"http://security.gentoo.org/glsa/glsa-200609-19.xml"},{"url":"http://security.gentoo.org/glsa/glsa-200610-01.xml","refsource":"MISC","name":"http://security.gentoo.org/glsa/glsa-200610-01.xml"},{"url":"http://securitytracker.com/id?1016858","refsource":"MISC","name":"http://securitytracker.com/id?1016858"},{"url":"http://securitytracker.com/id?1016859","refsource":"MISC","name":"http://securitytracker.com/id?1016859"},{"url":"http://securitytracker.com/id?1016860","refsource":"MISC","name":"http://securitytracker.com/id?1016860"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1","refsource":"MISC","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102781-1","refsource":"MISC","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102781-1"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm","refsource":"MISC","name":"http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2006-250.htm","refsource":"MISC","name":"http://support.avaya.com/elmodocs2/security/ASA-2006-250.htm"},{"url":"http://www.debian.org/security/2006/dsa-1192","refsource":"MISC","name":"http://www.debian.org/security/2006/dsa-1192"},{"url":"http://www.debian.org/security/2006/dsa-1210","refsource":"MISC","name":"http://www.debian.org/security/2006/dsa-1210"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200610-06.xml","refsource":"MISC","name":"http://www.gentoo.org/security/en/glsa/glsa-200610-06.xml"},{"url":"http://www.imc.org/ietf-openpgp/mail-archive/msg14307.html","refsource":"MISC","name":"http://www.imc.org/ietf-openpgp/mail-archive/msg14307.html"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2006:168","refsource":"MISC","name":"http://www.mandriva.com/security/advisories?name=MDKSA-2006:168"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2006:169","refsource":"MISC","name":"http://www.mandriva.com/security/advisories?name=MDKSA-2006:169"},{"url":"http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/","refsource":"MISC","name":"http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/"},{"url":"http://www.mozilla.org/security/announce/2006/mfsa2006-60.html","refsource":"MISC","name":"http://www.mozilla.org/security/announce/2006/mfsa2006-60.html"},{"url":"http://www.mozilla.org/security/announce/2006/mfsa2006-66.html","refsource":"MISC","name":"http://www.mozilla.org/security/announce/2006/mfsa2006-66.html"},{"url":"http://www.novell.com/linux/security/advisories/2006_54_mozilla.html","refsource":"MISC","name":"http://www.novell.com/linux/security/advisories/2006_54_mozilla.html"},{"url":"http://www.novell.com/linux/security/advisories/2006_55_ssl.html","refsource":"MISC","name":"http://www.novell.com/linux/security/advisories/2006_55_ssl.html"},{"url":"http://www.redhat.com/support/errata/RHSA-2006-0675.html","refsource":"MISC","name":"http://www.redhat.com/support/errata/RHSA-2006-0675.html"},{"url":"http://www.redhat.com/support/errata/RHSA-2006-0676.html","refsource":"MISC","name":"http://www.redhat.com/support/errata/RHSA-2006-0676.html"},{"url":"http://www.redhat.com/support/errata/RHSA-2006-0677.html","refsource":"MISC","name":"http://www.redhat.com/support/errata/RHSA-2006-0677.html"},{"url":"http://www.securityfocus.com/archive/1/446140/100/0/threaded","refsource":"MISC","name":"http://www.securityfocus.com/archive/1/446140/100/0/threaded"},{"url":"http://www.ubuntu.com/usn/usn-351-1","refsource":"MISC","name":"http://www.ubuntu.com/usn/usn-351-1"},{"url":"http://www.ubuntu.com/usn/usn-352-1","refsource":"MISC","name":"http://www.ubuntu.com/usn/usn-352-1"},{"url":"http://www.us-cert.gov/cas/techalerts/TA06-312A.html","refsource":"MISC","name":"http://www.us-cert.gov/cas/techalerts/TA06-312A.html"},{"url":"http://www.us.debian.org/security/2006/dsa-1191","refsource":"MISC","name":"http://www.us.debian.org/security/2006/dsa-1191"},{"url":"http://www.vupen.com/english/advisories/2006/3617","refsource":"MISC","name":"http://www.vupen.com/english/advisories/2006/3617"},{"url":"http://www.vupen.com/english/advisories/2006/3622","refsource":"MISC","name":"http://www.vupen.com/english/advisories/2006/3622"},{"url":"http://www.vupen.com/english/advisories/2006/3899","refsource":"MISC","name":"http://www.vupen.com/english/advisories/2006/3899"},{"url":"http://www.vupen.com/english/advisories/2007/0293","refsource":"MISC","name":"http://www.vupen.com/english/advisories/2007/0293"},{"url":"http://www.vupen.com/english/advisories/2007/1198","refsource":"MISC","name":"http://www.vupen.com/english/advisories/2007/1198"},{"url":"http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742","refsource":"MISC","name":"http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30098","refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30098"},{"url":"https://issues.rpath.com/browse/RPL-640","refsource":"MISC","name":"https://issues.rpath.com/browse/RPL-640"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11007","refsource":"MISC","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11007"}]}},"nvd":{"publishedDate":"2006-09-15 18:07:00","lastModifiedDate":"2023-11-07 01:59:00","problem_types":["CWE-20"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":4.9,"impactScore":4.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:*","versionEndIncluding":"3.11.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndIncluding":"1.5.0.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","versionEndIncluding":"1.5.0.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4340","Ordinal":"19672","Title":"CVE-2006-4340","CVE":"CVE-2006-4340","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4340","Ordinal":"1","NoteData":"Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339.  NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"4340","Ordinal":"2","NoteData":"2006-09-15","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4340","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}