CVE-2006-5462

Mozilla NSS <3.11.3 - Signature Forgery

Title source: llm
STIX 2.1

Description

Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.

References (54)

Core 54
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3748
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23883
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23235
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200612-08.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23013
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22770
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4387
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1225
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017180
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23009
Patch, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-312A.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1227
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22980
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0293
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0733.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24711
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23263
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22763
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22965
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-382-1
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0083
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0735.html
Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20061101-01-P
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017181
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_68_mozilla.html
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200612-07.xml
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1198
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23297
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22727
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22815
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0734.html
Patch, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/335392
Various Sources vendor-advisory x_refsource_hp
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30098
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22737
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22929
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23202
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200612-06.xml
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:206
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10478
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23197
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1224
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22066
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22817
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22722
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102781-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017182
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:205
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23287
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-381-1

Scores

EPSS 0.0263
EPSS Percentile 83.9%

Details

Status published
Products (22)
mozilla/firefox 1.5 (3 CPE variants)
mozilla/firefox 1.5.0.1
mozilla/firefox 1.5.0.2
mozilla/firefox 1.5.0.3
mozilla/firefox 1.5.0.4
mozilla/firefox 1.5.0.5
mozilla/firefox 1.5.0.6
mozilla/firefox 1.5.0.7
mozilla/network_security_services 3.11.3
mozilla/seamonkey 1.0 (4 CPE variants)
... and 12 more
Published Nov 08, 2006
Tracked Since Feb 18, 2026