LWN.net Logo

nss: signature forgery vulnerability

Package(s):nss CVE #(s):CVE-2006-4340
Created:September 15, 2006 Updated:October 18, 2006
Description: Daniel Bleichenbacher recently described an implementation error in RSA signature verification. For RSA keys with exponent 3 it is possible for an attacker to forge a signature that which would be incorrectly verified by the NSS library.
Alerts:
Gentoo 200610-06 2006-10-17
SuSE SUSE-SA:2006:055 2006-09-22
Fedora FEDORA-2006-979 2006-09-14

(Log in to post comments)

nss: signature forgery vulnerability

Posted Feb 4, 2007 19:30 UTC (Sun) by kreutzm (guest, #4700) [Link]

This is fixed in Debian already, for firefox see DSA 1192.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds