~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2006-5462

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDate: 2006-11-08
2
 
Candidate: CVE-2006-5462
3
 
References:
4
 
 https://usn.ubuntu.com/usn/usn-381-1
5
 
 https://usn.ubuntu.com/usn/usn-382-1
6
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5462
7
 
Description:
8
 
 Mozilla Network Security Service (NSS) library before 3.11.3, as used in
9
 
 Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey
10
 
 before 1.0.6, when using an RSA key with exponent 3, does not properly
11
 
 handle extra data in a signature, which allows remote attackers to forge
12
 
 signatures for SSL/TLS and email certificates. NOTE: this identifier is for
13
 
 unpatched product versions that were originally intended to be addressed by
14
 
 CVE-2006-4340.
15
 
Ubuntu-Description:
16
 
Notes:
17
 
Bugs:
18
 
dapper_firefox: released (1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1)
19
 
edgy_firefox: not-affected
20
 
feisty_firefox: not-affected
21
 
dapper_mozilla-thunderbird: released (1.5.0.13-0ubuntu0.6.06)
22
 
edgy_mozilla-thunderbird: released (1.5.0.13-0ubuntu0.6.10)
23
 
feisty_mozilla-thunderbird: released (1.5.0.13-0ubuntu0.7.04)
24
 
devel_mozilla-thunderbird: DNE
25
 
dapper_xulrunner: DNE
26
 
edgy_xulrunner: needed
27
 
feisty_xulrunner: released (1.8.0.10-3ubuntu1)
28
 
devel_xulrunner: released (1.8.0.10-3ubuntu1)
29
 
upstream_firefox: 
30
 
upstream_mozilla-thunderbird: 
31
 
upstream_xulrunner: