CVE Database
/

CVE-2006-5462

Back to search

CVE-2006-5462

Published: Nov 8, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2006-3748
vdb-entry
x_refsource_VUPEN
23883
third-party-advisory
x_refsource_SECUNIA
23235
third-party-advisory
x_refsource_SECUNIA
GLSA-200612-08
vendor-advisory
x_refsource_GENTOO
23013
third-party-advisory
x_refsource_SECUNIA
22770
third-party-advisory
x_refsource_SECUNIA
ADV-2006-4387
vdb-entry
x_refsource_VUPEN
DSA-1225
vendor-advisory
x_refsource_DEBIAN
1017180
vdb-entry
x_refsource_SECTRACK
23009
third-party-advisory
x_refsource_SECUNIA
TA06-312A
third-party-advisory
x_refsource_CERT
DSA-1227
vendor-advisory
x_refsource_DEBIAN
22980
third-party-advisory
x_refsource_SECUNIA
ADV-2007-0293
vdb-entry
x_refsource_VUPEN
RHSA-2006:0733
vendor-advisory
x_refsource_REDHAT
24711
third-party-advisory
x_refsource_SECUNIA
23263
third-party-advisory
x_refsource_SECUNIA
22763
third-party-advisory
x_refsource_SECUNIA
22965
third-party-advisory
x_refsource_SECUNIA
USN-382-1
vendor-advisory
x_refsource_UBUNTU
ADV-2008-0083
vdb-entry
x_refsource_VUPEN
RHSA-2006:0735
vendor-advisory
x_refsource_REDHAT
1017181
vdb-entry
x_refsource_SECTRACK
SUSE-SA:2006:068
vendor-advisory
x_refsource_SUSE
GLSA-200612-07
vendor-advisory
x_refsource_GENTOO
ADV-2007-1198
vdb-entry
x_refsource_VUPEN
23297
third-party-advisory
x_refsource_SECUNIA
22727
third-party-advisory
x_refsource_SECUNIA
22815
third-party-advisory
x_refsource_SECUNIA
RHSA-2006:0734
vendor-advisory
x_refsource_REDHAT
VU#335392
third-party-advisory
x_refsource_CERT-VN
SSRT061181
vendor-advisory
x_refsource_HP
mozilla-nss-security-bypass(30098)
vdb-entry
x_refsource_XF
22737
third-party-advisory
x_refsource_SECUNIA
22929
third-party-advisory
x_refsource_SECUNIA
23202
third-party-advisory
x_refsource_SECUNIA
GLSA-200612-06
vendor-advisory
x_refsource_GENTOO
HPSBUX02153
vendor-advisory
x_refsource_HP
MDKSA-2006:206
vendor-advisory
x_refsource_MANDRIVA
oval:org.mitre.oval:def:10478
vdb-entry
signature
x_refsource_OVAL
23197
third-party-advisory
x_refsource_SECUNIA
DSA-1224
vendor-advisory
x_refsource_DEBIAN
22066
third-party-advisory
x_refsource_SECUNIA
22817
third-party-advisory
x_refsource_SECUNIA
22722
third-party-advisory
x_refsource_SECUNIA
102781
vendor-advisory
x_refsource_SUNALERT
1017182
vdb-entry
x_refsource_SECTRACK
MDKSA-2006:205
vendor-advisory
x_refsource_MANDRIVA
23287
third-party-advisory
x_refsource_SECUNIA
USN-381-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now