IETF RFC 3279 X.509 Certificate MD5 Signature Collision Vulnerability
BID:33065
Info
IETF RFC 3279 X.509 Certificate MD5 Signature Collision Vulnerability
| Bugtraq ID: | 33065 |
| Class: | Design Error |
| CVE: |
CVE-2004-2761 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 30 2008 12:00AM |
| Updated: | May 02 2017 03:05AM |
| Credit: | Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik, and Benne de Weger. |
| Vulnerable: |
Yamaha SRT100 0 Yamaha RTX3000 0 Yamaha Rtx2000 0 Yamaha RTX1500 Yamaha RTX1100 Yamaha RTX1000 Yamaha RTV700 Yamaha RT300i Yamaha RT107e 0 Yamaha RT105 Yamaha RT104 0 Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Redhat Certificate Server 7.3 Oracle Trace File Analyzer (TFA) 0 Mozilla Network Security Services (NSS) 3.11.3 Mozilla Network Security Services (NSS) 3.12 Mozilla Network Security Services (NSS) 3.11 IETF RFC 3279: Algorithms and Identifiers for the Inter 0 HP VSR (Comware 7) 0 HP U200S and CS (Comware 5) 0 HP U200A and M (Comware 5) 0 HP SMB1920 (Comware 5) R1106 HP SMB1910 (Comware 5) R1108 HP SMB 1620 (Comware 5) R1105 HP SecBlade FW (Comware 5) 0 HP MSR4000 (Comware 7) 0 HP MSR3000 (Comware 7) 0 HP MSR2000 (Comware 7) 0 HP MSR20-1X (Comware 5) 0 HP MSR20 (Comware 5) 0 HP MSR1000 (Comware 7) 0 HP MSR1000 (Comware 5) 0 HP MSR 9XX (Comware 5) 0 HP MSR 93X (Comware 5) 0 HP MSR 50-G2 (Comware 5) 0 HP MSR 30-1X (Comware 5) 0 HP MSR 30-16 (Comware 5) 0 HP MSR 30 (Comware 5) 0 HP Moonshot 0 HP JG768AAE HP PCM+ to IMC Std Upg w/ 200-node E-LTU 0 HP JG767AAE HP IMC SmCnct WSM Vrtl Applnc SW E-LTU 0 HP JG766AAE HP IMC SmCnct Vrtl Applnc SW E-LTU 0 HP JG748AAE HP IMC Ent SW Plat w/ 50 Nodes E-LTU 0 HP JG747AAE HP IMC Std SW Plat w/ 50 Nodes E-LTU 0 HP JG660AAE HP IMC Smart Connect w/WLM VAE E-LTU 0 HP JG590AAE HP IMC Bsc WLAN Mgr SW Pltfm 50 AP E-LTU 0 HP JG550AAE HP PMM to IMC Bsc WLM Upgr w/150AP E-LTU 0 HP JG549AAE HP PCM+ to IMC Std Upgr w/200-node E-LTU 0 HP JG548AAE HP PCM+ to IMC Bsc Upgr w/50-node E-LTU 0 HP JG546AAE HP IMC Basic SW Platform w/50-node E-LTU 0 HP JF378AAE HP IMC Ent S/W Pltfrm w/200-node E-LTU 0 HP JF378A HP IMC Ent S/W Platform w/200-node Lic 0 HP JF377AAE HP IMC Std S/W Pltfrm w/100-node E-LTU 0 HP JF377A HP IMC Std S/W Platform w/100-node Lic 0 HP JF289AAE HP Enterprise Management System to Intelligent Manageme 0 HP JF288AAE HP Network Director to Intelligent Management Center 0 HP JD816A HP A-IMC Standard Edition Software DVD Media 0 HP JD815A HP IMC Std Platform w/100-node License 0 HP JD814A HP A-IMC Enterprise Edition Software DVD Media 0 HP JD808A HP IMC Ent Platform w/100-node License 0 HP JD126A HP IMC Ent S/W Platform w/100-node 0 HP JD125A HP IMC Std S/W Platform w/100-node 0 HP HSR6800 (Comware 7) 0 HP HSR6800 (Comware 5) 0 HP HSR6602 (Comware 5) 0 HP HP870 (Comware 5) 0 HP HP850 (Comware 5) 0 HP HP830 (Comware 5) 0 HP F5000-C/S (Comware 5) 0 HP F1000-E (Comware 5) 0 HP F1000-A-EI (Comware 5) 0 HP 9500E (Comware 5) 0 HP 7900 (Comware 7) R2122 HP 7500 (Comware 7) 0 HP 7500 (Comware 5) 0 HP 6600 RSE RU (Comware 5 Low Encryption SW) R3303P18 HP 6127XLG 0 HP 6125XLG 0 HP 5950 (Comware 7) 0 HP 5940 (Comware 7) 0 HP 5930 (Comware 7) 0 HP 5920 (Comware 7) 0 HP 5900 (Comware 7) 0 HP 5830 (Comware 5) 0 HP 5800 (Comware 5) 0 HP 5500SI (Comware 5) 0 HP 5500 HI (Comware 5) 0 HP 5500 EI (Comware 5) 0 HP 5130 (Comware 7) R3108P03 HP 5120 SI (Comware 5) 0 HP 5120 EI (Comware 5) 0 HP 4800G (Comware 5) 0 HP 4500G (Comware 5) 0 HP 4210G (Comware 5) 0 HP 12500 (Comware 7) 0 HP 12500 (Comware 5) 0 HP 10500 (Comware 7) 0 HP 10500 (Comware 5) 0 F5 ARX 6.4 F5 ARX 6.3 F5 ARX 6.2 F5 ARX 6.1.1 F5 ARX 6.1 F5 ARX 6.0 Cisco IOS CA 0 |
| Not Vulnerable: |
Oracle Trace File Analyzer (TFA) 12.1.2.8.4 Mozilla Network Security Services (NSS) 3.12.2 |
Discussion
IETF RFC 3279 X.509 Certificate MD5 Signature Collision Vulnerability
X.509 certificates are prone to a signature-collision attack when signed with the MD5 algorithm. Attackers may take advantage of this issue to generate pairs of different, valid X.509 certificates that share a common signature.
An attacker is most likely to exploit this issue to conduct phishing attacks or to impersonate legitimate sites by taking advantage of malicious certificates. Other attacks are likely possible.
NOTE: This attack is an extension of the weakness covered in BID 11849 (MD5 Message Digest Algorithm Hash Collision Weakness).
X.509 certificates are prone to a signature-collision attack when signed with the MD5 algorithm. Attackers may take advantage of this issue to generate pairs of different, valid X.509 certificates that share a common signature.
An attacker is most likely to exploit this issue to conduct phishing attacks or to impersonate legitimate sites by taking advantage of malicious certificates. Other attacks are likely possible.
NOTE: This attack is an extension of the weakness covered in BID 11849 (MD5 Message Digest Algorithm Hash Collision Weakness).
Exploit / POC
IETF RFC 3279 X.509 Certificate MD5 Signature Collision Vulnerability
This attack has been demonstrated; please see the references for more information.
This attack has been demonstrated; please see the references for more information.
Solution / Fix
IETF RFC 3279 X.509 Certificate MD5 Signature Collision Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 7.10 powerpc
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.10 powerpc
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu Ubuntu Linux 6.06 LTS sparc
Ubuntu Ubuntu Linux 8.04 LTS amd64
Ubuntu Ubuntu Linux 7.10 sparc
Ubuntu Ubuntu Linux 8.10 sparc
Ubuntu Ubuntu Linux 8.10 amd64
Ubuntu Ubuntu Linux 8.10 i386
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 7.10 powerpc
-
Ubuntu libnss3-0d-dbg_3.11.5-3ubuntu0.7.10.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-0d-dbg_3.11. 5-3ubuntu0.7.10.2_powerpc.deb -
Ubuntu libnss3-0d_3.11.5-3ubuntu0.7.10.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-0d_3.11.5-3u buntu0.7.10.2_powerpc.deb -
Ubuntu libnss3-dev_3.11.5-3ubuntu0.7.10.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-dev_3.11.5-3 ubuntu0.7.10.2_powerpc.deb -
Ubuntu libnss3-tools_3.11.5-3ubuntu0.7.10.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/universe/n/nss/libnss3-tools_3. 11.5-3ubuntu0.7.10.2_powerpc.deb
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu libnss3-0d_3.12.0.3-0ubuntu0.8.04.5_powerpc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-0d_3.12.0.3-0ubuntu0.8 .04.5_powerpc.deb -
Ubuntu libnss3-1d-dbg_3.12.0.3-0ubuntu0.8.04.5_powerpc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-1d-dbg_3.12.0.3-0ubunt u0.8.04.5_powerpc.deb -
Ubuntu libnss3-1d_3.12.0.3-0ubuntu0.8.04.5_powerpc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-1d_3.12.0.3-0ubuntu0.8 .04.5_powerpc.deb -
Ubuntu libnss3-dev_3.12.0.3-0ubuntu0.8.04.5_powerpc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-dev_3.12.0.3-0ubuntu0. 8.04.5_powerpc.deb -
Ubuntu libnss3-tools_3.12.0.3-0ubuntu0.8.04.5_powerpc.deb
http://ports.ubuntu.com/pool/universe/n/nss/libnss3-tools_3.12.0.3-0ub untu0.8.04.5_powerpc.deb
Ubuntu Ubuntu Linux 8.10 powerpc
-
Ubuntu libnss3-0d_3.12.0.3-0ubuntu5.8.10.1_powerpc.deb
http://ports.ubuntu.com/pool/universe/n/nss/libnss3-0d_3.12.0.3-0ubunt u5.8.10.1_powerpc.deb -
Ubuntu libnss3-1d-dbg_3.12.0.3-0ubuntu5.8.10.1_powerpc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-1d-dbg_3.12.0.3-0ubunt u5.8.10.1_powerpc.deb -
Ubuntu libnss3-1d_3.12.0.3-0ubuntu5.8.10.1_powerpc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-1d_3.12.0.3-0ubuntu5.8 .10.1_powerpc.deb -
Ubuntu libnss3-dev_3.12.0.3-0ubuntu5.8.10.1_powerpc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-dev_3.12.0.3-0ubuntu5. 8.10.1_powerpc.deb -
Ubuntu libnss3-tools_3.12.0.3-0ubuntu5.8.10.1_powerpc.deb
http://ports.ubuntu.com/pool/universe/n/nss/libnss3-tools_3.12.0.3-0ub untu5.8.10.1_powerpc.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu libnss3-0d_3.12.0.3-0ubuntu0.8.04.5_sparc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-0d_3.12.0.3-0ubuntu0.8 .04.5_sparc.deb -
Ubuntu libnss3-1d-dbg_3.12.0.3-0ubuntu0.8.04.5_sparc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-1d-dbg_3.12.0.3-0ubunt u0.8.04.5_sparc.deb -
Ubuntu libnss3-1d_3.12.0.3-0ubuntu0.8.04.5_sparc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-1d_3.12.0.3-0ubuntu0.8 .04.5_sparc.deb -
Ubuntu libnss3-dev_3.12.0.3-0ubuntu0.8.04.5_sparc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-dev_3.12.0.3-0ubuntu0. 8.04.5_sparc.deb -
Ubuntu libnss3-tools_3.12.0.3-0ubuntu0.8.04.5_sparc.deb
http://ports.ubuntu.com/pool/universe/n/nss/libnss3-tools_3.12.0.3-0ub untu0.8.04.5_sparc.deb
Ubuntu Ubuntu Linux 6.06 LTS sparc
-
Ubuntu firefox-dbg_1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dbg_1.5. dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb -
Ubuntu firefox-dev_1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-dev_1.5. dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb -
Ubuntu firefox-dom-inspector_1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/universe/f/firefox/firefox-dom- inspector_1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb -
Ubuntu firefox-gnome-support_1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox-gnome-su pport_1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb -
Ubuntu firefox_1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_1.5.dfsg +1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb -
Ubuntu libnspr-dev_1.firefox1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnspr-dev_1.fi refox1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb -
Ubuntu libnspr4_1.firefox1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnspr4_1.firef ox1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb -
Ubuntu libnss-dev_1.firefox1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnss-dev_1.fir efox1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb -
Ubuntu libnss3_1.firefox1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/firefox/libnss3_1.firefo x1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_sparc.deb -
Ubuntu mozilla-firefox-dev_1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/f/firefox/mozilla-fire fox-dev_1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_all.deb -
Ubuntu mozilla-firefox_1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/f/firefox/mozilla-firefox_ 1.5.dfsg+1.5.0.15~prepatch080614k-0ubuntu2_all.deb
Ubuntu Ubuntu Linux 8.04 LTS amd64
-
Ubuntu libnss3-0d_3.12.0.3-0ubuntu0.8.04.5_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-0d_3.12.0.3- 0ubuntu0.8.04.5_amd64.deb -
Ubuntu libnss3-1d-dbg_3.12.0.3-0ubuntu0.8.04.5_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-1d-dbg_3.12. 0.3-0ubuntu0.8.04.5_amd64.deb -
Ubuntu libnss3-1d_3.12.0.3-0ubuntu0.8.04.5_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-1d_3.12.0.3- 0ubuntu0.8.04.5_amd64.deb -
Ubuntu libnss3-dev_3.12.0.3-0ubuntu0.8.04.5_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-dev_3.12.0.3 -0ubuntu0.8.04.5_amd64.deb -
Ubuntu libnss3-tools_3.12.0.3-0ubuntu0.8.04.5_amd64.deb
http://security.ubuntu.com/ubuntu/pool/universe/n/nss/libnss3-tools_3. 12.0.3-0ubuntu0.8.04.5_amd64.deb
Ubuntu Ubuntu Linux 7.10 sparc
-
Ubuntu libnss3-0d-dbg_3.11.5-3ubuntu0.7.10.2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-0d-dbg_3.11. 5-3ubuntu0.7.10.2_sparc.deb -
Ubuntu libnss3-0d_3.11.5-3ubuntu0.7.10.2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-0d_3.11.5-3u buntu0.7.10.2_sparc.deb -
Ubuntu libnss3-dev_3.11.5-3ubuntu0.7.10.2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-dev_3.11.5-3 ubuntu0.7.10.2_sparc.deb -
Ubuntu libnss3-tools_3.11.5-3ubuntu0.7.10.2_sparc.deb
http://security.ubuntu.com/ubuntu/pool/universe/n/nss/libnss3-tools_3. 11.5-3ubuntu0.7.10.2_sparc.deb
Ubuntu Ubuntu Linux 8.10 sparc
-
Ubuntu libnss3-0d_3.12.0.3-0ubuntu5.8.10.1_sparc.deb
http://ports.ubuntu.com/pool/universe/n/nss/libnss3-0d_3.12.0.3-0ubunt u5.8.10.1_sparc.deb -
Ubuntu libnss3-1d-dbg_3.12.0.3-0ubuntu5.8.10.1_sparc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-1d-dbg_3.12.0.3-0ubunt u5.8.10.1_sparc.deb -
Ubuntu libnss3-1d_3.12.0.3-0ubuntu5.8.10.1_sparc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-1d_3.12.0.3-0ubuntu5.8 .10.1_sparc.deb -
Ubuntu libnss3-dev_3.12.0.3-0ubuntu5.8.10.1_sparc.deb
http://ports.ubuntu.com/pool/main/n/nss/libnss3-dev_3.12.0.3-0ubuntu5. 8.10.1_sparc.deb -
Ubuntu libnss3-tools_3.12.0.3-0ubuntu5.8.10.1_sparc.deb
http://ports.ubuntu.com/pool/universe/n/nss/libnss3-tools_3.12.0.3-0ub untu5.8.10.1_sparc.deb
Ubuntu Ubuntu Linux 8.10 amd64
-
Ubuntu libnss3-0d_3.12.0.3-0ubuntu5.8.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/universe/n/nss/libnss3-0d_3.12. 0.3-0ubuntu5.8.10.1_amd64.deb -
Ubuntu libnss3-1d-dbg_3.12.0.3-0ubuntu5.8.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-1d-dbg_3.12. 0.3-0ubuntu5.8.10.1_amd64.deb -
Ubuntu libnss3-1d_3.12.0.3-0ubuntu5.8.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-1d_3.12.0.3- 0ubuntu5.8.10.1_amd64.deb -
Ubuntu libnss3-dev_3.12.0.3-0ubuntu5.8.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-dev_3.12.0.3 -0ubuntu5.8.10.1_amd64.deb -
Ubuntu libnss3-tools_3.12.0.3-0ubuntu5.8.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/universe/n/nss/libnss3-tools_3. 12.0.3-0ubuntu5.8.10.1_amd64.deb
Ubuntu Ubuntu Linux 8.10 i386
-
Ubuntu libnss3-0d_3.12.0.3-0ubuntu5.8.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/universe/n/nss/libnss3-0d_3.12. 0.3-0ubuntu5.8.10.1_i386.deb -
Ubuntu libnss3-1d-dbg_3.12.0.3-0ubuntu5.8.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-1d-dbg_3.12. 0.3-0ubuntu5.8.10.1_i386.deb -
Ubuntu libnss3-1d_3.12.0.3-0ubuntu5.8.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-1d_3.12.0.3- 0ubuntu5.8.10.1_i386.deb -
Ubuntu libnss3-dev_3.12.0.3-0ubuntu5.8.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/n/nss/libnss3-dev_3.12.0.3 -0ubuntu5.8.10.1_i386.deb -
Ubuntu libnss3-tools_3.12.0.3-0ubuntu5.8.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/universe/n/nss/libnss3-tools_3. 12.0.3-0ubuntu5.8.10.1_i386.deb
References
IETF RFC 3279 X.509 Certificate MD5 Signature Collision Vulnerability
References:
References:
- Creating a rogue CA certificate (Alexander Sotirov)
- Information regarding MD5 collisions problem (Microsoft)
- MD5 considered harmful today - Creating a rogue CA certificate (Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, D)
- MD5 Weaknesses Could Lead to Certificate Forgery (Mozilla)
- Microsoft Security Advisory (961509) (Microsoft)
- Network Security Services (NSS) Product Page (Mozilla)
- RFC 3279 - Algorithms and Identifiers for the Internet X.509 Public Key Infrastr (IETF)
- RT Series Security FAQ (Yamaha)
- TC TrustCenter Response to SSL Vulnerability Paper (TC TrustCenter)
- This morning's MD5 attack - resolved (Verisign)
- VU#836068 (US-CERT)
- Weak MD5 Cryptographic Algorithm Allows for Certification Authority Certificate (Cisco)
- Cisco Security Response: MD5 Hashes May Allow for Certificate Spoofing (Cisco)
- HPSBHF03654 rev.1 - HPE iMC PLAT Network Products using SSL/TLS, Multiple Remote (HP)
- HPSBHF03673 rev.1 - HPE Comware 5 and Comware 7 Network Products using SSL/TLS, (HP)
- Oracle Critical Patch Update Advisory - April 2017 (Oracle)
- sol15578: MD5 Message-Digest Algorithm vulnerability CVE-2004-2761 (F5 Networks)
- TN 7690 - Are Entrust certificates susceptible to the md5 vulnerability? (Entrust)