CVE-2006-4340
published 2006-09-15CVE-2006-4340: Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before…
PriorityP416medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
2.15%
80.0th percentile
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axtls_project | axtls | <= 2.1.3 | — |
| debian | firefox | < firefox 1.5.dfsg+1.5.0.7-1 (sid) | firefox 1.5.dfsg+1.5.0.7-1 (sid) |
| debian | firefox | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | firefox-esr | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | thunderbird | < firefox 1.5.dfsg+1.5.0.7-1 (sid) | firefox 1.5.dfsg+1.5.0.7-1 (sid) |
| mozilla | firefox | <= 1.5.0.6 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | network_security_services | <= 3.11.2 | — |
| mozilla | network_security_services | — | — |
| mozilla | seamonkey | <= 1.0.4 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | thunderbird | <= 1.5.0.6 | — |
| mozilla | thunderbird | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.3MEDIUM
vendor_ubuntu7.6HIGH
vendor_debian4.3HIGH
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2006-11-08·CVSS 4.0
CVE-2006-5462 [MEDIUM] security flaw
security flaw
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
Ubuntu
Mozilla vulnerabilities
vendor_ubuntu·2006-10-10·CVSS 7.5
CVE-2006-2788 [HIGH] Mozilla vulnerabilities
Title: Mozilla vulnerabilities
Summary: Mozilla vulnerabilities
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening
a malicious URL. (CVE-2006-2788, CVE-2006-3805, CVE-2006-3806,
CVE-2006-3807, CVE-2006-3809, CVE-2006-3811, CVE-2006-4565,
CVE-2006-4568, CVE-2006-4571)
A bug was found in the script handler for automatic proxy
configuration. A malicious proxy could send scripts which could
execute arbitrary code with the user's privileges. (CVE-2006-3808)
The NSS library did not sufficiently check the padding of PKCS #1 v1.5
signatures if the exponent of the public key is 3 (which is widely
used for CAs). This could be exploited to forge valid signatures
without the need of the secret key. (CVE-2006-4340
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2006-09-25·CVSS 7.6
CVE-2006-4253 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening
a malicious email containing JavaScript. Please note that JavaScript
is disabled by default for emails, and it is not recommended to enable
it. (CVE-2006-4253, CVE-2006-4565, CVE-2006-4566, CVE-2006-4571)
The NSS library did not sufficiently check the padding of PKCS #1 v1.5
signatures if the exponent of the public key is 3 (which is widely
used for CAs). This could be exploited to forge valid signatures
without the need of the secret key. (CVE-2006-4340)
Jon Oberheide reported a way how a remote attacker could trick users
into downloading arbitrary extensions with circumventing t
Ubuntu
firefox vulnerabilities
vendor_ubuntu·2006-09-23·CVSS 7.6
CVE-2006-4571 [HIGH] firefox vulnerabilities
Title: firefox vulnerabilities
Summary: firefox vulnerabilities
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening
a malicious web page containing JavaScript. (CVE-2006-4253,
CVE-2006-4565, CVE-2006-4566, CVE-2006-4568, CVE-2006-4569
CVE-2006-4571)
The NSS library did not sufficiently check the padding of PKCS #1 v1.5
signatures if the exponent of the public key is 3 (which is widely
used for CAs). This could be exploited to forge valid signatures
without the need of the secret key. (CVE-2006-4340)
Jon Oberheide reported a way how a remote attacker could trick users
into downloading arbitrary extensions with circumventing the normal
SSL certificate check. The attacker would have to be in a position to
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2006-09-22·CVSS 7.5
CVE-2006-3113 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
This update upgrades Thunderbird from 1.0.8 to 1.5.0.7. This step was
necessary since the 1.0.x series is not supported by upstream any
more.
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening
a malicious email containing JavaScript. Please note that JavaScript
is disabled by default for emails, and it is not recommended to enable
it. (CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3805,
CVE-2006-3806, CVE-2006-3807, CVE-2006-3809, CVE-2006-3810,
CVE-2006-3811, CVE-2006-3812, CVE-2006-4253, CVE-2006-4565,
CVE-2006-4566, CVE-2006-4571)
A buffer overflow has been discovered in the handling of .vcard files.
By tricking a user
Red Hat
security flaw
vendor_redhat·2006-09-15·CVSS 4.3
CVE-2006-4340 [MEDIUM] security flaw
security flaw
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
Debian
CVE-2006-4340: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla...
vendor_debian·2006·CVSS 4.3
CVE-2006-4340 [MEDIUM] CVE-2006-4340: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla...
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.7-1)
Debian
CVE-2006-5462: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla...
vendor_debian·2006·CVSS 4.0
CVE-2006-5462 [MEDIUM] CVE-2006-5462: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla...
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
Scope: local
sid: resolved (fixed in 45.0-1)
GHSA
GHSA-wj3m-9v78-x5g4: In sig_verify() in x509
ghsa_unreviewed·2022-05-14·CVSS 4.0
CVE-2018-16150 [MEDIUM] CWE-347 GHSA-wj3m-9v78-x5g4: In sig_verify() in x509
In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not reject excess data after the hash value. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation through fake X.509 certificates. This is a variant of CVE-2006-4340.
GHSA
GHSA-q7vf-rjwh-chxv: Mozilla Network Security Service (NSS) library before 3
ghsa_unreviewed·2022-05-03·CVSS 4.3
CVE-2006-4340 [MEDIUM] CWE-20 GHSA-q7vf-rjwh-chxv: Mozilla Network Security Service (NSS) library before 3
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
GHSA
GHSA-rmhr-q7w5-3ffq: Mozilla Network Security Service (NSS) library before 3
ghsa_unreviewed·2022-05-03·CVSS 4.0
CVE-2006-5462 [MEDIUM] GHSA-rmhr-q7w5-3ffq: Mozilla Network Security Service (NSS) library before 3
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
OSV
CVE-2006-5462: Mozilla Network Security Service (NSS) library before 3
osv·2006-11-08·CVSS 4.0
CVE-2006-5462 [MEDIUM] CVE-2006-5462: Mozilla Network Security Service (NSS) library before 3
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
OSV
CVE-2006-4340: Mozilla Network Security Service (NSS) library before 3
osv·2006-09-15·CVSS 4.3
CVE-2006-4340 [MEDIUM] CVE-2006-4340: Mozilla Network Security Service (NSS) library before 3
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-4340 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2006-4340 [MEDIUM] CVE-2006-4340 security flaw
CVE-2006-4340 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
Bugzilla
CVE-2006-5462 security flaw
bugzilla·2018-08-16·CVSS 4.0
CVE-2006-5462 [MEDIUM] CVE-2006-5462 security flaw
CVE-2006-5462 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
Bugzilla
CVE-2006-4340 nss needs update
bugzilla·2006-09-15·CVSS 4.0
CVE-2006-4340 [MEDIUM] CVE-2006-4340 nss needs update
CVE-2006-4340 nss needs update
FC6 needs NSS update to correct CVE-2006-4340
Discussion:
The pre-FC6 Rawhide tree has been updated to include
nss-3.11.3-2
Bugzilla
CVE-2006-4340 Various SeaMonkey security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4568 CVE-2006-4570 CVE-2006-4571)
bugzilla·2006-09-14·CVSS 7.6
CVE-2006-4340 [HIGH] CVE-2006-4340 Various SeaMonkey security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4568 CVE-2006-4570 CVE-2006-4571)
CVE-2006-4340 Various SeaMonkey security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4568 CVE-2006-4570 CVE-2006-4571)
** MFSA-2006-57 **
Two flaws were found in the way Firefox processed certain
regular expressions. A malicious web page could crash the
browser or possibly execute arbitrary code as the user running
Firefox. (CVE-2006-4565, CVE-2006-4566)
CVE-2006-4565 https://bugzilla.mozilla.org/show_bug.cgi?id=346090
CVE-2006-4566 https://bugzilla.mozilla.org/show_bug.cgi?id=346794
impact=critical,public=20060914
** MFSA-2006-58 **
A flaw was found in the Firefox auto-update verfication
system. An attacker who has the ability to spoof a victim's
DNS could get Firefox to download and install malicious code.
In order to exploit this issue an attacker would also need to
Bugzilla
CVE-2006-4340 Various Firefox security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4568 CVE-2006-4569 CVE-2006-4571)
bugzilla·2006-09-14·CVSS 7.6
CVE-2006-4340 [HIGH] CVE-2006-4340 Various Firefox security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4568 CVE-2006-4569 CVE-2006-4571)
CVE-2006-4340 Various Firefox security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4568 CVE-2006-4569 CVE-2006-4571)
** MFSA-2006-57 **
Two flaws were found in the way Firefox processed certain
regular expressions. A malicious web page could crash the
browser or possibly execute arbitrary code as the user running
Firefox. (CVE-2006-4565, CVE-2006-4566)
CVE-2006-4565 https://bugzilla.mozilla.org/show_bug.cgi?id=346090
CVE-2006-4566 https://bugzilla.mozilla.org/show_bug.cgi?id=346794
impact=critical,public=20060914
** MFSA-2006-58 **
A flaw was found in the Firefox auto-update verfication
system. An attacker who has the ability to spoof a victim's
DNS could get Firefox to download and install malicious code.
In order to exploit this issue an attacker would a
Bugzilla
CVE-2006-4340 Various Thunderbird security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4570 CVE-2006-4571)
bugzilla·2006-09-14·CVSS 7.6
CVE-2006-4340 [HIGH] CVE-2006-4340 Various Thunderbird security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4570 CVE-2006-4571)
CVE-2006-4340 Various Thunderbird security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4570 CVE-2006-4571)
** MFSA-2006-57 **
Two flaws were found in the way Firefox processed certain
regular expressions. A malicious web page could crash the
browser or possibly execute arbitrary code as the user running
Firefox. (CVE-2006-4565, CVE-2006-4566)
CVE-2006-4565 https://bugzilla.mozilla.org/show_bug.cgi?id=346090
CVE-2006-4566 https://bugzilla.mozilla.org/show_bug.cgi?id=346794
** MFSA-2006-58 **
A flaw was found in the Firefox auto-update verfication
system. An attacker who has the ability to spoof a victim's
DNS could get Firefox to download and install malicious code.
In order to exploit this issue an attacker would also need to
get a victim to previously acc
ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.aschttp://secunia.com/advisories/21903http://secunia.com/advisories/21906http://secunia.com/advisories/21915http://secunia.com/advisories/21916http://secunia.com/advisories/21939http://secunia.com/advisories/21940http://secunia.com/advisories/21949http://secunia.com/advisories/21950http://secunia.com/advisories/22001http://secunia.com/advisories/22025http://secunia.com/advisories/22036http://secunia.com/advisories/22044http://secunia.com/advisories/22055http://secunia.com/advisories/22056http://secunia.com/advisories/22066http://secunia.com/advisories/22074http://secunia.com/advisories/22088http://secunia.com/advisories/22195http://secunia.com/advisories/22210http://secunia.com/advisories/22226http://secunia.com/advisories/22247http://secunia.com/advisories/22274http://secunia.com/advisories/22299http://secunia.com/advisories/22342http://secunia.com/advisories/22422http://secunia.com/advisories/22446http://secunia.com/advisories/22849http://secunia.com/advisories/22992http://secunia.com/advisories/23883http://secunia.com/advisories/24711http://security.gentoo.org/glsa/glsa-200609-19.xmlhttp://security.gentoo.org/glsa/glsa-200610-01.xmlhttp://securitytracker.com/id?1016858http://securitytracker.com/id?1016859http://securitytracker.com/id?1016860http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102781-1http://support.avaya.com/elmodocs2/security/ASA-2006-224.htmhttp://support.avaya.com/elmodocs2/security/ASA-2006-250.htmhttp://www.debian.org/security/2006/dsa-1192http://www.debian.org/security/2006/dsa-1210http://www.gentoo.org/security/en/glsa/glsa-200610-06.xmlhttp://www.imc.org/ietf-openpgp/mail-archive/msg14307.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:168http://www.mandriva.com/security/advisories?name=MDKSA-2006:169http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/http://www.mozilla.org/security/announce/2006/mfsa2006-60.htmlhttp://www.mozilla.org/security/announce/2006/mfsa2006-66.htmlhttp://www.novell.com/linux/security/advisories/2006_54_mozilla.htmlhttp://www.novell.com/linux/security/advisories/2006_55_ssl.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0675.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0676.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0677.htmlhttp://www.securityfocus.com/archive/1/446140/100/0/threadedhttp://www.ubuntu.com/usn/usn-350-1http://www.ubuntu.com/usn/usn-351-1http://www.ubuntu.com/usn/usn-352-1http://www.ubuntu.com/usn/usn-354-1http://www.ubuntu.com/usn/usn-361-1http://www.us-cert.gov/cas/techalerts/TA06-312A.htmlhttp://www.us.debian.org/security/2006/dsa-1191http://www.vupen.com/english/advisories/2006/3617http://www.vupen.com/english/advisories/2006/3622http://www.vupen.com/english/advisories/2006/3748http://www.vupen.com/english/advisories/2006/3899http://www.vupen.com/english/advisories/2007/0293http://www.vupen.com/english/advisories/2007/1198http://www.vupen.com/english/advisories/2008/0083http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742https://exchange.xforce.ibmcloud.com/vulnerabilities/30098https://issues.rpath.com/browse/RPL-640https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11007ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.aschttp://secunia.com/advisories/21903http://secunia.com/advisories/21906http://secunia.com/advisories/21915http://secunia.com/advisories/21916http://secunia.com/advisories/21939http://secunia.com/advisories/21940http://secunia.com/advisories/21949http://secunia.com/advisories/21950http://secunia.com/advisories/22001http://secunia.com/advisories/22025http://secunia.com/advisories/22036http://secunia.com/advisories/22044http://secunia.com/advisories/22055http://secunia.com/advisories/22056http://secunia.com/advisories/22066http://secunia.com/advisories/22074http://secunia.com/advisories/22088http://secunia.com/advisories/22195http://secunia.com/advisories/22210http://secunia.com/advisories/22226http://secunia.com/advisories/22247http://secunia.com/advisories/22274http://secunia.com/advisories/22299http://secunia.com/advisories/22342http://secunia.com/advisories/22422http://secunia.com/advisories/22446
+ 46 more references
2006-09-15
Published