CVE-2006-4340
Last modified
CVE-2006-4340 is a vulnerability of currently unknown severity. Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. EPSS estimates a 2.15% chance of exploitation in the next 30 days.
Description
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 1.5.0.6 |
| Mozilla | Network Security Services | <= 3.11.2 |
| Mozilla | Seamonkey | <= 1.0.4 |
| Mozilla | Thunderbird | <= 1.5.0.6 |
References
- http://secunia.com/advisories/21903Vendor Advisory
- http://secunia.com/advisories/21906Patch, Vendor Advisory
- http://secunia.com/advisories/21915Vendor Advisory
- http://secunia.com/advisories/21916Vendor Advisory
- http://secunia.com/advisories/21939Vendor Advisory
- http://secunia.com/advisories/21940Vendor Advisory
- http://secunia.com/advisories/21949Patch, Vendor Advisory
- http://secunia.com/advisories/21950Vendor Advisory
- http://secunia.com/advisories/22001Vendor Advisory
- http://secunia.com/advisories/22025Vendor Advisory
- http://secunia.com/advisories/22036Vendor Advisory
- http://secunia.com/advisories/22055Vendor Advisory
- http://secunia.com/advisories/22074Vendor Advisory
- http://secunia.com/advisories/22088Vendor Advisory
- http://secunia.com/advisories/22210Vendor Advisory
- http://secunia.com/advisories/22226Vendor Advisory
- http://secunia.com/advisories/22247Vendor Advisory
- http://secunia.com/advisories/22274Vendor Advisory
- http://secunia.com/advisories/22299Vendor Advisory
- http://secunia.com/advisories/22342Vendor Advisory
- http://secunia.com/advisories/22422Vendor Advisory
- http://secunia.com/advisories/22446Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0675.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0676.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0677.htmlPatch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA06-312A.htmlUS Government Resource
- http://secunia.com/advisories/21903Vendor Advisory
- http://secunia.com/advisories/21906Patch, Vendor Advisory
- http://secunia.com/advisories/21915Vendor Advisory
- http://secunia.com/advisories/21916Vendor Advisory
- http://secunia.com/advisories/21939Vendor Advisory
- http://secunia.com/advisories/21940Vendor Advisory
- http://secunia.com/advisories/21949Patch, Vendor Advisory
- http://secunia.com/advisories/21950Vendor Advisory
- http://secunia.com/advisories/22001Vendor Advisory
- http://secunia.com/advisories/22025Vendor Advisory
- http://secunia.com/advisories/22036Vendor Advisory
- http://secunia.com/advisories/22055Vendor Advisory
- http://secunia.com/advisories/22074Vendor Advisory
- http://secunia.com/advisories/22088Vendor Advisory
- http://secunia.com/advisories/22210Vendor Advisory
- http://secunia.com/advisories/22226Vendor Advisory
- http://secunia.com/advisories/22247Vendor Advisory
- http://secunia.com/advisories/22274Vendor Advisory
- http://secunia.com/advisories/22299Vendor Advisory
- http://secunia.com/advisories/22342Vendor Advisory
- http://secunia.com/advisories/22422Vendor Advisory
- http://secunia.com/advisories/22446Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0675.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0676.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0677.htmlPatch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA06-312A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-4340?
How severe is CVE-2006-4340?
How do I fix CVE-2006-4340?
Are you affected by CVE-2006-4340?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
