blog.mozilla.com
http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery CVE-2004-2761
CRITICAL
MD5 - Message Digest Algorithm Hash Collision
Record summary
CVE-2004-2761 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 28, 2026 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBMD5 - Message Digest Algorithm Hash CollisionExploitDB exploitby Dan KaminskyNot analyzed1 file
References
Showing 12 of 27blogs.technet.com
http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx 33826Third-party advisory
http://secunia.com/advisories/33826 34281Third-party advisory
http://secunia.com/advisories/34281 42181Third-party advisory
http://secunia.com/advisories/42181 4866Third-party advisory
http://securityreason.com/securityalert/4866 1024697vdb entry
http://securitytracker.com/id?1024697 20090115 MD5 Hashes May Allow for Certificate SpoofingVendor advisory
http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html doxpara.com
http://www.doxpara.com/research/md5/md5_someday.pdf VU#836068Third-party advisory
http://www.kb.cert.org/vuls/id/836068 microsoft.com
http://www.microsoft.com/technet/security/advisory/961509.mspx phreedom.org
http://www.phreedom.org/research/rogue-ca