Security Advisory

CVE-2006-4790

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-09-14 19:00:00
Last updated 2024-08-07 19:23:41
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.