CVE-2006-5201

UnknownEPSS 3.08%

Last modified

CVE-2006-5201 is a vulnerability of currently unknown severity. Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.. EPSS estimates a 3.08% chance of exploitation in the next 30 days.

Description

Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.

Metrics

EPSS Probability
3.08%

86.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
SunNssAll versions
SunSecure Global DesktopAll versions
SunStarofficeAll versions
SunSolaris9.0
SunSolaris10.0
SunSunos5.8
SunJdk1.5.0
SunJre1.3.1
SunJre1.3.1_2
SunJre1.3.1_03
SunJre1.3.1_04
SunJre1.3.1_05
SunJre1.3.1_06
SunJre1.3.1_07
SunJre1.3.1_08
SunJre1.3.1_09
SunJre1.3.1_10
SunJre1.3.1_11
SunJre1.3.1_12
SunJre1.3.1_13
SunJre1.3.1_14
SunJre1.3.1_15
SunJre1.3.1_16
SunJre1.3.1_17
SunJre1.3.1_18
SunJre1.3.1_19
SunJre1.4.2
SunJre1.4.2_1
SunJre1.4.2_2
SunJre1.4.2_3
SunJre1.4.2_4
SunJre1.4.2_5
SunJre1.4.2_6
SunJre1.4.2_7
SunJre1.4.2_8
SunJre1.4.2_9
SunJre1.4.2_10
SunJre1.4.2_11
SunJre1.4.2_12
SunJre1.5.0
SunSdk1.3.1
SunSdk1.3.1_01
SunSdk1.3.1_01a
SunSdk1.3.1_02
SunSdk1.3.1_03
SunSdk1.3.1_04
SunSdk1.3.1_05
SunSdk1.3.1_06
SunSdk1.3.1_07
SunSdk1.3.1_08

Showing 50 of 78 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-5201?
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.
How severe is CVE-2006-5201?
Severity scoring for CVE-2006-5201 is pending analysis. The EPSS model estimates a 3.08% probability of exploitation in the next 30 days.
How do I fix CVE-2006-5201?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-5201?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST