CVE-2006-5462

NameCVE-2006-5462
DescriptionMozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1224-1, DSA-1225-1, DSA-1227-1
NVD severitymedium (attack range: remote)
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
icedove (PTS)squeeze (security), squeeze3.0.11-1+squeeze15fixed
wheezy31.3.0-1~deb7u1fixed
wheezy (security)31.4.0-1~deb7u1fixed
jessie31.4.0-2fixed
sid31.5.0-1fixed
iceweasel (PTS)squeeze (security), squeeze3.5.16-20fixed
wheezy31.3.0esr-1~deb7u1fixed
wheezy (security)31.5.0esr-1~deb7u1fixed
jessie, sid31.5.0esr-1fixed
xulrunner (PTS)wheezy, wheezy (security)24.8.1esr-2~deb7u1fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
firefoxsource(unstable)(unfixed)high
icedovesource(unstable)1.5.0.8-1medium
iceweaselsource(unstable)2.0+dfsg-1high
mozillasource(unstable)(unfixed)high
mozillasourcesarge2:1.7.8-1sarge8mediumDSA-1224-1
mozilla-firefoxsourcesarge1.0.4-2sarge13mediumDSA-1225-1
mozilla-thunderbirdsourcesarge1.0.2-2.sarge1.0.8d.1mediumDSA-1227-1
xulrunnersource(unstable)1.8.0.8-1high

Notes

MFSA-2006-66
this is the similar to CVE-2006-4339, see also CVE-2006-4340
the fixes for CVE-2006-4340 were incomplete

Search for package or bug name: Reporting problems