Description
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
References (54)
Core 54
Core References
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3748
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23883
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23235
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200612-08.xml
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23013
Vendor Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-246.htm
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22770
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4387
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1225
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1017180
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23009
Patch x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=356215
Patch, US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-312A.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1227
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22980
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0293
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0733.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24711
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23263
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22763
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22965
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-382-1
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0083
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0735.html
Vendor Advisory vendor-advisory
x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20061101-01-P
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1017181
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_68_mozilla.html
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200612-07.xml
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1198
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23297
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22727
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22815
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0734.html
Patch, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/335392
Various Sources vendor-advisory
x_refsource_hp
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30098
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22737
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22929
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23202
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200612-06.xml
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:206
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10478
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23197
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1224
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22066
Patch x_refsource_confirm
http://www.mozilla.org/security/announce/2006/mfsa2006-66.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22817
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22722
Vendor Advisory vendor-advisory
x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102781-1
Patch x_refsource_misc
http://www.mozilla.org/security/announce/2006/mfsa2006-60.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1017182
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:205
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23287
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-381-1
Scores
EPSS
0.0263
EPSS Percentile
83.9%
Details
Status
published
Products (22)
mozilla/firefox
1.5 (3 CPE variants)
mozilla/firefox
1.5.0.1
mozilla/firefox
1.5.0.2
mozilla/firefox
1.5.0.3
mozilla/firefox
1.5.0.4
mozilla/firefox
1.5.0.5
mozilla/firefox
1.5.0.6
mozilla/firefox
1.5.0.7
mozilla/network_security_services
3.11.3
mozilla/seamonkey
1.0 (4 CPE variants)
... and 12 more
Published
Nov 08, 2006
Tracked Since
Feb 18, 2026