Vulnerability CVE-2006-4339: Information

Description

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

Severity: MEDIUM (4.3)

Published: Sept. 5, 2006
Modified: Oct. 18, 2018
Error type identifier: CWE-310

References to Advisories, Solutions, and Tools

Hyperlink
Resource
[ietf-openpgp] 20060827 Bleichenbacher's RSA signature forgery based on implementation error
    http://www.openssl.org/news/secadv_20060905.txt
    • Patch
    • Vendor Advisory
    21709
    • Patch
    • Vendor Advisory
    USN-339-1
    • Patch
    19849
    • Patch
    https://issues.rpath.com/browse/RPL-616
      DSA-1173
      • Patch
      DSA-1174
      • Patch
      FreeBSD-SA-06:19
        GLSA-200609-05
          MDKSA-2006:161
            [3.9] 20060908 011: SECURITY FIX: September 8, 2006
              RHSA-2006:0661
              • Vendor Advisory
              28549
                1016791
                  21778
                  • Vendor Advisory
                  21785
                  • Vendor Advisory
                  21812
                  • Vendor Advisory
                  21823
                  • Vendor Advisory
                  21852
                  • Vendor Advisory
                  21791
                  • Vendor Advisory
                  21767
                  • Vendor Advisory
                  21776
                  • Vendor Advisory
                  http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/
                    VU#845620
                    • US Government Resource
                    21873
                    • Vendor Advisory
                    21906
                    • Vendor Advisory
                    21846
                    • Vendor Advisory
                    http://support.avaya.com/elmodocs2/security/ASA-2006-188.htm
                      SSA:2006-257-02
                        21927
                        • Vendor Advisory
                        21870
                        • Vendor Advisory
                        20060901-01-P
                          22036
                          • Vendor Advisory
                          http://www.opera.com/support/search/supsearch.dml?index=845
                            21982
                            • Vendor Advisory
                            GLSA-200609-18
                              SUSE-SA:2006:055
                                21930
                                • Vendor Advisory
                                22161
                                • Vendor Advisory
                                22259
                                • Vendor Advisory
                                22260
                                • Vendor Advisory
                                http://openvpn.net/changelog.html
                                  102648
                                    22226
                                    • Vendor Advisory
                                    22232
                                    • Vendor Advisory
                                    http://www.serv-u.com/releasenotes/
                                      22284
                                        GLSA-200610-06
                                          102657
                                            22325
                                              22446
                                                SUSE-SA:2006:061
                                                  22509
                                                    http://support.attachmate.com/techdocs/2137.html
                                                      http://www.bluecoat.com/support/knowledge/openSSL_RSA_Signature_forgery.html
                                                        http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3117
                                                          102656
                                                            22513
                                                              22523
                                                                22545
                                                                  22585
                                                                    http://www.arkoon.fr/upload/alertes/40AK-2006-04-FR-1.1_SSL360_OPENSSL_RSA.pdf
                                                                      OpenPKG-SA-2006.029
                                                                        SSA:2006-310-01
                                                                          102696
                                                                            22733
                                                                              22671
                                                                                22689
                                                                                  20061108 Multiple Vulnerabilities in OpenSSL library
                                                                                    20061108 Multiple Vulnerabilities in OpenSSL Library
                                                                                      22758
                                                                                        22799
                                                                                          http://www.sybase.com/detail?id=1047991
                                                                                            102686
                                                                                              22711
                                                                                                22934
                                                                                                  22936
                                                                                                    22937
                                                                                                      22938
                                                                                                        22939
                                                                                                          22940
                                                                                                            22949
                                                                                                              MDKSA-2006:207
                                                                                                                SUSE-SR:2006:026
                                                                                                                  22948
                                                                                                                    102722
                                                                                                                      APPLE-SA-2006-11-28
                                                                                                                        TA06-333A
                                                                                                                        • US Government Resource
                                                                                                                        23155
                                                                                                                          102744
                                                                                                                            102759
                                                                                                                              23455
                                                                                                                                http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html
                                                                                                                                  http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html
                                                                                                                                    http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html
                                                                                                                                      http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html
                                                                                                                                        http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html
                                                                                                                                          http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html
                                                                                                                                            23680
                                                                                                                                              23794
                                                                                                                                                http://support.attachmate.com/techdocs/2127.html
                                                                                                                                                  http://support.attachmate.com/techdocs/2128.html
                                                                                                                                                    OpenPKG-SA-2006.018
                                                                                                                                                      RHSA-2007:0062
                                                                                                                                                        RHSA-2007:0072
                                                                                                                                                          RHSA-2007:0073
                                                                                                                                                            SUSE-SA:2007:010
                                                                                                                                                              1017522
                                                                                                                                                                23841
                                                                                                                                                                  23915
                                                                                                                                                                    22044
                                                                                                                                                                      22932
                                                                                                                                                                        24099
                                                                                                                                                                          24950
                                                                                                                                                                            24930
                                                                                                                                                                              BEA07-169.00
                                                                                                                                                                                25284
                                                                                                                                                                                  https://secure-support.novell.com/KanisaPlatform/Publishing/41/3143224_f.SAL_Public.html
                                                                                                                                                                                    https://issues.rpath.com/browse/RPL-1633
                                                                                                                                                                                      MDKSA-2006:177
                                                                                                                                                                                        MDKSA-2006:178
                                                                                                                                                                                          22083
                                                                                                                                                                                            25399
                                                                                                                                                                                              25649
                                                                                                                                                                                                22066
                                                                                                                                                                                                  26329
                                                                                                                                                                                                    26893
                                                                                                                                                                                                      APPLE-SA-2007-12-14
                                                                                                                                                                                                        28115
                                                                                                                                                                                                          201247
                                                                                                                                                                                                            201534
                                                                                                                                                                                                              [security-announce] 20080317 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues
                                                                                                                                                                                                                http://www.vmware.com/security/advisories/VMSA-2008-0005.html
                                                                                                                                                                                                                  http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html
                                                                                                                                                                                                                    http://www.vmware.com/support/player/doc/releasenotes_player.html
                                                                                                                                                                                                                      http://www.vmware.com/support/player2/doc/releasenotes_player2.html
                                                                                                                                                                                                                        http://www.vmware.com/support/server/doc/releasenotes_server.html
                                                                                                                                                                                                                          http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html
                                                                                                                                                                                                                            http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html
                                                                                                                                                                                                                              28276
                                                                                                                                                                                                                                200708
                                                                                                                                                                                                                                  31492
                                                                                                                                                                                                                                    RHSA-2008:0629
                                                                                                                                                                                                                                      SSRT071304
                                                                                                                                                                                                                                        38567
                                                                                                                                                                                                                                          http://www.openoffice.org/security/cves/CVE-2006-4339.html
                                                                                                                                                                                                                                            ADV-2010-0366
                                                                                                                                                                                                                                              38568
                                                                                                                                                                                                                                                1000148
                                                                                                                                                                                                                                                  ADV-2007-2315
                                                                                                                                                                                                                                                    ADV-2007-2163
                                                                                                                                                                                                                                                      ADV-2007-1401
                                                                                                                                                                                                                                                        ADV-2006-4329
                                                                                                                                                                                                                                                          ADV-2006-3730
                                                                                                                                                                                                                                                            ADV-2006-3936
                                                                                                                                                                                                                                                              ADV-2006-3453
                                                                                                                                                                                                                                                                ADV-2006-4586
                                                                                                                                                                                                                                                                  ADV-2008-0905
                                                                                                                                                                                                                                                                    ADV-2007-1945
                                                                                                                                                                                                                                                                      ADV-2006-4744
                                                                                                                                                                                                                                                                        ADV-2007-1815
                                                                                                                                                                                                                                                                          ADV-2007-0254
                                                                                                                                                                                                                                                                            ADV-2006-4417
                                                                                                                                                                                                                                                                              ADV-2006-3748
                                                                                                                                                                                                                                                                                ADV-2006-4750
                                                                                                                                                                                                                                                                                  SSRT071299
                                                                                                                                                                                                                                                                                    ADV-2006-3566
                                                                                                                                                                                                                                                                                      ADV-2006-5146
                                                                                                                                                                                                                                                                                        ADV-2006-3793
                                                                                                                                                                                                                                                                                          ADV-2006-4366
                                                                                                                                                                                                                                                                                            ADV-2007-4224
                                                                                                                                                                                                                                                                                              ADV-2006-4327
                                                                                                                                                                                                                                                                                                ADV-2006-4206
                                                                                                                                                                                                                                                                                                  ADV-2007-0343
                                                                                                                                                                                                                                                                                                    ADV-2006-4207
                                                                                                                                                                                                                                                                                                      ADV-2007-2783
                                                                                                                                                                                                                                                                                                        ADV-2006-4216
                                                                                                                                                                                                                                                                                                          ADV-2006-3899
                                                                                                                                                                                                                                                                                                            ADV-2006-4205
                                                                                                                                                                                                                                                                                                              SSRT090208
                                                                                                                                                                                                                                                                                                                http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html
                                                                                                                                                                                                                                                                                                                  JVNDB-2012-000079
                                                                                                                                                                                                                                                                                                                    JVN#51615542
                                                                                                                                                                                                                                                                                                                      SSRT061181
                                                                                                                                                                                                                                                                                                                        http://docs.info.apple.com/article.html?artnum=304829
                                                                                                                                                                                                                                                                                                                          http://docs.info.apple.com/article.html?artnum=307177
                                                                                                                                                                                                                                                                                                                            HPSBMA02250
                                                                                                                                                                                                                                                                                                                              SSRT061273
                                                                                                                                                                                                                                                                                                                                GLSA-201408-19
                                                                                                                                                                                                                                                                                                                                  60799
                                                                                                                                                                                                                                                                                                                                    41818
                                                                                                                                                                                                                                                                                                                                      [bind-announce] 20061103 Internet Systems Consortium Security Advisory. [revised]
                                                                                                                                                                                                                                                                                                                                        openssl-rsa-security-bypass(28755)
                                                                                                                                                                                                                                                                                                                                          oval:org.mitre.oval:def:11656
                                                                                                                                                                                                                                                                                                                                            20080318 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues
                                                                                                                                                                                                                                                                                                                                              20070110 VMware ESX server security updates
                                                                                                                                                                                                                                                                                                                                                HPSBUX02165
                                                                                                                                                                                                                                                                                                                                                  20060912 ERRATA: [ GLSA 200609-05 ] OpenSSL, AMD64 x86 emulation base libraries: RSA signature forgery
                                                                                                                                                                                                                                                                                                                                                    20060905 rPSA-2006-0163-1 openssl openssl-scripts
                                                                                                                                                                                                                                                                                                                                                        1. Configuration 1

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.5a:beta2:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6i:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.3:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.7c:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.5:beta1:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6d:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.1c:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.7j:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6a:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
                                                                                                                                                                                                                                                                                                                                                          End including
                                                                                                                                                                                                                                                                                                                                                          0.9.7

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.4:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6a:beta2:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.5a:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6f:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6:beta3:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6l:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.7g:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6e:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.7d:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6b:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.7e:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.7b:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6a:beta1:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6k:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6g:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6:beta2:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.3a:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6h:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.7i:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.7h:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6j:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6c:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6:beta1:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6m:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.5:beta2:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.2b:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.5:*:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.5a:beta1:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.6a:beta3:*:*:*:*:*:*

                                                                                                                                                                                                                                                                                                                                                          cpe:2.3:a:openssl:openssl:0.9.7f:*:*:*:*:*:*:*