← Back

CVE-2006-5201

nvd nist
Published: Oct 10, 2006Modified: Apr 23, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:H/Au:N/C:N/I:P/A:P
Exploitability: 4.9 / Impact: 4.9
Source: NVD

Description

Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.

Affected (95)

9 products
Nss
Secure Global Desktop
Staroffice
Solaris
Sunos
Jdk
Jre
Sdk
Jsse
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 10.0
Version 9.0
Version 5.8
Configuration C
10 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 1.5.0
Version 1.5.0 update1
Version 1.5.0 update2
Version 1.5.0 update3
Version 1.5.0 update4
Version 1.5.0 update5
Version 1.5.0 update6
Version 1.5.0 update7
Version 1.5.0 update7_b03
Version 1.5.0 update8
Configuration D
41 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 1.3.1
Version 1.3.1_03
Version 1.3.1_04
Version 1.3.1_05
Version 1.3.1_06
Version 1.3.1_07
Version 1.3.1_08
Version 1.3.1_09
Version 1.3.1_10
Version 1.3.1_11
Version 1.3.1_12
Version 1.3.1_13
Version 1.3.1_14
Version 1.3.1_15
Version 1.3.1_16
Version 1.3.1_17
Version 1.3.1_18
Version 1.3.1_19
Version 1.3.1_2
Version 1.4.2
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_1
Version 1.4.2_2
Version 1.4.2_3
Version 1.4.2_4
Version 1.4.2_5
Version 1.4.2_6
Version 1.4.2_7
Version 1.4.2_8
Version 1.4.2_9
Version 1.5.0
Version 1.5.0 update1
Version 1.5.0 update2
Version 1.5.0 update3
Version 1.5.0 update4
Version 1.5.0 update5
Version 1.5.0 update6
Version 1.5.0 update7
Version 1.5.0 update8
Configuration E
34 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 1.3.1
Version 1.3.1_01
Version 1.3.1_01a
Version 1.3.1_02
Version 1.3.1_03
Version 1.3.1_04
Version 1.3.1_05
Version 1.3.1_06
Version 1.3.1_07
Version 1.3.1_08
Version 1.3.1_09
Version 1.3.1_10
Version 1.3.1_11
Version 1.3.1_12
Version 1.3.1_13
Version 1.3.1_14
Version 1.3.1_15
Version 1.3.1_16
Version 1.3.1_17
Version 1.3.1_18
Version 1.3.1_19
Version 1.4.2
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_1
Version 1.4.2_2
Version 1.4.2_3
Version 1.4.2_4
Version 1.4.2_5
Version 1.4.2_6
Version 1.4.2_7
Version 1.4.2_8
Version 1.4.2_9
Configuration F
4 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 1.0.3
Version 1.0.3_01
Version 1.0.3_02
Version 1.0.3_03

References (22)

Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Permissions Required
Source: cve@mitre.org
Permissions Required
Source: cve@mitre.org
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.