CVE-2006-5201
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6)…
Does this matter?
Lower severity and a low EPSS score (3.36%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:H/Au:N/C:N/I:P/A:P
- EPSS
- 3.36% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- sun/nss · sun/secure global desktop · sun/staroffice · sun/solaris · sun/sunos · sun/jdk · sun/jre · sun/sdk · sun/jsse
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/22204Patch, Third Party Advisory
- http://secunia.com/advisories/22226Third Party Advisory
- http://secunia.com/advisories/22325Third Party Advisory
- http://secunia.com/advisories/22992Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102657-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2006-250.htmThird Party Advisory
- http://www.kb.cert.org/vuls/id/845620Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2006/3898Permissions Required
- http://www.vupen.com/english/advisories/2006/3899Permissions Required
- http://www.vupen.com/english/advisories/2006/3960Permissions Required
- http://secunia.com/advisories/22204Patch, Third Party Advisory
- http://secunia.com/advisories/22226Third Party Advisory
- http://secunia.com/advisories/22325Third Party Advisory
- http://secunia.com/advisories/22992Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102657-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2006-250.htmThird Party Advisory
- http://www.kb.cert.org/vuls/id/845620Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2006/3898Permissions Required
- http://www.vupen.com/english/advisories/2006/3899Permissions Required
- http://www.vupen.com/english/advisories/2006/3960Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.