SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-5201

Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6)…

MEDIUM 4.0EPSS 3.36%

Does this matter?

Lower severity and a low EPSS score (3.36%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.

CVSS 2.0
4.0 MEDIUMAV:N/AC:H/Au:N/C:N/I:P/A:P
EPSS
3.36% probability · 88th percentile
CISA KEV
Not listed
Affected
sun/nss · sun/secure global desktop · sun/staroffice · sun/solaris · sun/sunos · sun/jdk · sun/jre · sun/sdk · sun/jsse
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.