CVE-2006-4340
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature,…
Does this matter?
Lower severity and a low EPSS score (2.28%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
- EPSS
- 2.28% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- mozilla/firefox · mozilla/network security services · mozilla/seamonkey · mozilla/thunderbird
- Source
- secalert@redhat.com
References
- ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc
- http://secunia.com/advisories/21903Vendor Advisory
- http://secunia.com/advisories/21906Patch, Vendor Advisory
- http://secunia.com/advisories/21915Vendor Advisory
- http://secunia.com/advisories/21916Vendor Advisory
- http://secunia.com/advisories/21939Vendor Advisory
- http://secunia.com/advisories/21940Vendor Advisory
- http://secunia.com/advisories/21949Patch, Vendor Advisory
- http://secunia.com/advisories/21950Vendor Advisory
- http://secunia.com/advisories/22001Vendor Advisory
- http://secunia.com/advisories/22025Vendor Advisory
- http://secunia.com/advisories/22036Vendor Advisory
- http://secunia.com/advisories/22044
- http://secunia.com/advisories/22055Vendor Advisory
- http://secunia.com/advisories/22056
- http://secunia.com/advisories/22066
- http://secunia.com/advisories/22074Vendor Advisory
- http://secunia.com/advisories/22088Vendor Advisory
- http://secunia.com/advisories/22195
- http://secunia.com/advisories/22210Vendor Advisory
- http://secunia.com/advisories/22226Vendor Advisory
- http://secunia.com/advisories/22247Vendor Advisory
- http://secunia.com/advisories/22274Vendor Advisory
- http://secunia.com/advisories/22299Vendor Advisory
- http://secunia.com/advisories/22342Vendor Advisory
- http://secunia.com/advisories/22422Vendor Advisory
- http://secunia.com/advisories/22446Vendor Advisory
- http://secunia.com/advisories/22849
- http://secunia.com/advisories/22992
- http://secunia.com/advisories/23883
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.