CVE-2006-4790
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.
verify.c en GnuTLS anterior a 1.4.4, cuando usamos una llave RSA con exponente 3, no maneja correctamente el exceso de datos en el campo digestAlgorithm.parameters al generar un hash, el cual permite a un atacante remoto falsificar una firma PKCS #1 v1.5 que es firmada por esa llave RSA y evita que GnuTLS verifique correctamente X.509 y otros certificados que utilicen PKCS, es una variante de CVE-2006-4339.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-09-13 CVE Reserved
- 2006-09-14 CVE Published
- 2024-05-20 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (32)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.gnu.org/software/gnutls/security.html | 2017-10-11 | |
http://www.redhat.com/support/errata/RHSA-2006-0680.html | 2017-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.0.17 Search vendor "Gnu" for product "Gnutls" and version "1.0.17" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.0.18 Search vendor "Gnu" for product "Gnutls" and version "1.0.18" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.0.19 Search vendor "Gnu" for product "Gnutls" and version "1.0.19" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.0.20 Search vendor "Gnu" for product "Gnutls" and version "1.0.20" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.0.21 Search vendor "Gnu" for product "Gnutls" and version "1.0.21" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.0.22 Search vendor "Gnu" for product "Gnutls" and version "1.0.22" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.0.23 Search vendor "Gnu" for product "Gnutls" and version "1.0.23" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.0.24 Search vendor "Gnu" for product "Gnutls" and version "1.0.24" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.0.25 Search vendor "Gnu" for product "Gnutls" and version "1.0.25" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.1.14 Search vendor "Gnu" for product "Gnutls" and version "1.1.14" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.1.15 Search vendor "Gnu" for product "Gnutls" and version "1.1.15" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.1.16 Search vendor "Gnu" for product "Gnutls" and version "1.1.16" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.1.17 Search vendor "Gnu" for product "Gnutls" and version "1.1.17" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.1.18 Search vendor "Gnu" for product "Gnutls" and version "1.1.18" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.1.19 Search vendor "Gnu" for product "Gnutls" and version "1.1.19" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.1.20 Search vendor "Gnu" for product "Gnutls" and version "1.1.20" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.1.21 Search vendor "Gnu" for product "Gnutls" and version "1.1.21" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.1.22 Search vendor "Gnu" for product "Gnutls" and version "1.1.22" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.1.23 Search vendor "Gnu" for product "Gnutls" and version "1.1.23" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.0 Search vendor "Gnu" for product "Gnutls" and version "1.2.0" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.1 Search vendor "Gnu" for product "Gnutls" and version "1.2.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.2 Search vendor "Gnu" for product "Gnutls" and version "1.2.2" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.3 Search vendor "Gnu" for product "Gnutls" and version "1.2.3" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.4 Search vendor "Gnu" for product "Gnutls" and version "1.2.4" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.5 Search vendor "Gnu" for product "Gnutls" and version "1.2.5" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.6 Search vendor "Gnu" for product "Gnutls" and version "1.2.6" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.7 Search vendor "Gnu" for product "Gnutls" and version "1.2.7" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.8 Search vendor "Gnu" for product "Gnutls" and version "1.2.8" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.8.1a1 Search vendor "Gnu" for product "Gnutls" and version "1.2.8.1a1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.9 Search vendor "Gnu" for product "Gnutls" and version "1.2.9" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.10 Search vendor "Gnu" for product "Gnutls" and version "1.2.10" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.2.11 Search vendor "Gnu" for product "Gnutls" and version "1.2.11" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.3.0 Search vendor "Gnu" for product "Gnutls" and version "1.3.0" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.3.1 Search vendor "Gnu" for product "Gnutls" and version "1.3.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.3.2 Search vendor "Gnu" for product "Gnutls" and version "1.3.2" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.3.3 Search vendor "Gnu" for product "Gnutls" and version "1.3.3" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.3.4 Search vendor "Gnu" for product "Gnutls" and version "1.3.4" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.3.5 Search vendor "Gnu" for product "Gnutls" and version "1.3.5" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.4.0 Search vendor "Gnu" for product "Gnutls" and version "1.4.0" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Gnutls Search vendor "Gnu" for product "Gnutls" | 1.4.1 Search vendor "Gnu" for product "Gnutls" and version "1.4.1" | - |
Affected
|