CVE-2005-4900
published 2016-10-14CVE-2005-4900: SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of…
PriorityP426medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.94%
57.4th percentile
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gradle | < gradle 4.4.1-18 (bookworm) | gradle 4.4.1-18 (bookworm) |
| github.com | sylabs_sif_v2 | >= 0 < 2.8.1 | 2.8.1 |
| chrome | <= 47.0.2526.111 | — | |
| gradle | gradle | < 6.0 | 6.0 |
| gradle | gradle | >= 0 < 4.4.1-18 | 4.4.1-18 |
| gradle | gradle | >= 0 < 4.4.1-18 | 4.4.1-18 |
| gradle | gradle | >= 0 < 4.4.1-18 | 4.4.1-18 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa5.9MEDIUM
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gradle: PGP signing plugin security bypass
vendor_redhat·2019-09-16·CVSS 5.9
CVE-2019-16370 [MEDIUM] CWE-20 gradle: PGP signing plugin security bypass
gradle: PGP signing plugin security bypass
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
Package: gradle (Red Hat JBoss Enterprise Web Server 3) - Out of support scope
Debian
CVE-2019-16370: gradle - The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which...
vendor_debian·2019·CVSS 5.9
CVE-2019-16370 [MEDIUM] CVE-2019-16370: gradle - The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which...
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
Scope: local
bookworm: resolved (fixed in 4.4.1-18)
bullseye: open
forky: resolved (fixed in 4.4.1-18)
sid: resolved (fixed in 4.4.1-18)
trixie: resolved (fixed in 4.4.1-18)
GHSA
SIF's Digital Signature Hash Algorithms Not Validated
ghsa·2022-10-06·CVSS 5.0
CVE-2022-39237 [MEDIUM] CWE-327 SIF's Digital Signature Hash Algorithms Not Validated
SIF's Digital Signature Hash Algorithms Not Validated
### Impact
The `github.com/sylabs/sif/v2/pkg/integrity` package does not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures.
### Patches
A patch is available in version >= v2.8.1 of the module. Users are encouraged to upgrade.
The patch is commit https://github.com/sylabs/sif/commit/07fb86029a12e3210f6131e065570124605daeaa
### Workarounds
Users may independently validate that the hash algorithm(s) used for metadata digest(s) and signature hash are cryptographically secure.
### References
* [CVE-2004-2761](https://nvd.nist.gov/vuln/detail/cve-2004-2761)
* [CVE-2005-4900](https://nvd.nist.gov/vuln/detail/cve-2005-4900)
### For more information
If you have any questions or comme
OSV
SIF's Digital Signature Hash Algorithms Not Validated
osv·2022-10-06·CVSS 5.0
CVE-2022-39237 [MEDIUM] SIF's Digital Signature Hash Algorithms Not Validated
SIF's Digital Signature Hash Algorithms Not Validated
### Impact
The `github.com/sylabs/sif/v2/pkg/integrity` package does not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures.
### Patches
A patch is available in version >= v2.8.1 of the module. Users are encouraged to upgrade.
The patch is commit https://github.com/sylabs/sif/commit/07fb86029a12e3210f6131e065570124605daeaa
### Workarounds
Users may independently validate that the hash algorithm(s) used for metadata digest(s) and signature hash are cryptographically secure.
### References
* [CVE-2004-2761](https://nvd.nist.gov/vuln/detail/cve-2004-2761)
* [CVE-2005-4900](https://nvd.nist.gov/vuln/detail/cve-2005-4900)
### For more information
If you have any questions or comme
GHSA
Use of a weak cryptographic algorithm in Gradle
ghsa·2022-05-24·CVSS 5.9
CVE-2019-16370 [MEDIUM] CWE-327 Use of a weak cryptographic algorithm in Gradle
Use of a weak cryptographic algorithm in Gradle
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
OSV
Use of a weak cryptographic algorithm in Gradle
osv·2022-05-24·CVSS 5.9
CVE-2019-16370 [MEDIUM] Use of a weak cryptographic algorithm in Gradle
Use of a weak cryptographic algorithm in Gradle
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
GHSA
GHSA-xj59-9qjv-fr54: SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the
ghsa_unreviewed·2022-05-01
CVE-2005-4900 [MEDIUM] CWE-326 GHSA-xj59-9qjv-fr54: SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.
OSV
CVE-2019-16370: The PGP signing plugin in Gradle before 6
osv·2019-09-16·CVSS 5.9
CVE-2019-16370 [MEDIUM] CVE-2019-16370: The PGP signing plugin in Gradle before 6
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
No detection rules found.
No public exploits indexed.
CWE
Use of Weak Hash
mitre_cwe
CWE-328 Use of Weak Hash
CWE-328: Use of Weak Hash
The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).
A hash function is defined as an algorithm that maps arbitrarily sized data into a fixed-sized digest (output) such that the following properties hold: The algorithm is not invertible (also called "one-way" or "not reversible") The algorithm is deterministic; the same input produces the same digest every time Building on this definition, a cryptographic hash function must also ensure that a malicious actor
CAPEC
Creating a Rogue Certification Authority Certificate
mitre_capec
[CRITICAL] Creating a Rogue Certification Authority Certificate
CAPEC-459: Creating a Rogue Certification Authority Certificate
An adversary exploits a weakness resulting from using a hashing algorithm with weak collision resistance to generate certificate signing requests (CSR) that contain collision blocks in their "to be signed" parts. The adversary submits one CSR to be signed by a trusted certificate authority then uses the signed blob to make a second certificate appear signed by said certificate authority. Due to the hash collision, both certificates, though different, hash to the same value and so the signed blob works just as well in the second certificate. The net effect is that the adversary's second X.509 certificate, which the Certification Authority has never seen, is now signed and validated by that Certification Authority.
Execution F
http://ia.cr/2007/474http://shattered.io/http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1http://www.securityfocus.com/bid/12577https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/https://kc.mcafee.com/corporate/index?page=content&id=SB10340https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.htmlhttps://security.googleblog.com/2017/02/announcing-first-sha1-collision.htmlhttps://sites.google.com/site/itstheshappeninghttps://www.schneier.com/blog/archives/2005/02/sha1_broken.htmlhttps://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.htmlhttp://ia.cr/2007/474http://shattered.io/http://www.cwi.nl/news/2017/cwi-and-google-announce-first-collision-industry-security-standard-sha-1http://www.securityfocus.com/bid/12577https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/https://kc.mcafee.com/corporate/index?page=content&id=SB10340https://security.googleblog.com/2015/12/an-update-on-sha-1-certificates-in.htmlhttps://security.googleblog.com/2017/02/announcing-first-sha1-collision.htmlhttps://sites.google.com/site/itstheshappeninghttps://www.schneier.com/blog/archives/2005/02/sha1_broken.htmlhttps://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html
2016-10-14
Published