OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

Subscriptions

Vendors Products
Openssl Subscribe
Openssl Subscribe
Enterprise Linux Subscribe
Network Satellite Subscribe
Rhel Extras Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1173-1 New openssl packages fix RSA signature forgery cryptographic weakness
Debian DSA Debian DSA DSA-1174-1 New openssl096 packages fix RSA signature forgery cryptographic weakness
EUVD EUVD EUVD-2006-4327 OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.
Ubuntu USN Ubuntu USN USN-339-1 OpenSSL vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc cve-icon cve-icon
http://dev2dev.bea.com/pub/advisory/238 cve-icon cve-icon
http://docs.info.apple.com/article.html?artnum=304829 cve-icon cve-icon
http://docs.info.apple.com/article.html?artnum=307177 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01070495 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771 cve-icon cve-icon
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540 cve-icon cve-icon
http://jvn.jp/en/jp/JVN51615542/index.html cve-icon cve-icon
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-000079.html cve-icon cve-icon
http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html cve-icon cve-icon
http://lists.vmware.com/pipermail/security-announce/2008/000008.html cve-icon cve-icon
http://marc.info/?l=bind-announce&m=116253119512445&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=130497311408250&w=2 cve-icon cve-icon
http://openvpn.net/changelog.html cve-icon cve-icon
http://secunia.com/advisories/21709 cve-icon cve-icon
http://secunia.com/advisories/21767 cve-icon cve-icon
http://secunia.com/advisories/21776 cve-icon cve-icon
http://secunia.com/advisories/21778 cve-icon cve-icon
http://secunia.com/advisories/21785 cve-icon cve-icon
http://secunia.com/advisories/21791 cve-icon cve-icon
http://secunia.com/advisories/21812 cve-icon cve-icon
http://secunia.com/advisories/21823 cve-icon cve-icon
http://secunia.com/advisories/21846 cve-icon cve-icon
http://secunia.com/advisories/21852 cve-icon cve-icon
http://secunia.com/advisories/21870 cve-icon cve-icon
http://secunia.com/advisories/21873 cve-icon cve-icon
http://secunia.com/advisories/21906 cve-icon cve-icon
http://secunia.com/advisories/21927 cve-icon cve-icon
http://secunia.com/advisories/21930 cve-icon cve-icon
http://secunia.com/advisories/21982 cve-icon cve-icon
http://secunia.com/advisories/22036 cve-icon cve-icon
http://secunia.com/advisories/22044 cve-icon cve-icon
http://secunia.com/advisories/22066 cve-icon cve-icon
http://secunia.com/advisories/22161 cve-icon cve-icon
http://secunia.com/advisories/22226 cve-icon cve-icon
http://secunia.com/advisories/22232 cve-icon cve-icon
http://secunia.com/advisories/22259 cve-icon cve-icon
http://secunia.com/advisories/22260 cve-icon cve-icon
http://secunia.com/advisories/22284 cve-icon cve-icon
http://secunia.com/advisories/22325 cve-icon cve-icon
http://secunia.com/advisories/22446 cve-icon cve-icon
http://secunia.com/advisories/22509 cve-icon cve-icon
http://secunia.com/advisories/22513 cve-icon cve-icon
http://secunia.com/advisories/22523 cve-icon cve-icon
http://secunia.com/advisories/22545 cve-icon cve-icon
http://secunia.com/advisories/22585 cve-icon cve-icon
http://secunia.com/advisories/22671 cve-icon cve-icon
http://secunia.com/advisories/22689 cve-icon cve-icon
http://secunia.com/advisories/22711 cve-icon cve-icon
http://secunia.com/advisories/22733 cve-icon cve-icon
http://secunia.com/advisories/22758 cve-icon cve-icon
http://secunia.com/advisories/22799 cve-icon cve-icon
http://secunia.com/advisories/22932 cve-icon cve-icon
http://secunia.com/advisories/22934 cve-icon cve-icon
http://secunia.com/advisories/22936 cve-icon cve-icon
http://secunia.com/advisories/22937 cve-icon cve-icon
http://secunia.com/advisories/22938 cve-icon cve-icon
http://secunia.com/advisories/22939 cve-icon cve-icon
http://secunia.com/advisories/22940 cve-icon cve-icon
http://secunia.com/advisories/22948 cve-icon cve-icon
http://secunia.com/advisories/22949 cve-icon cve-icon
http://secunia.com/advisories/23155 cve-icon cve-icon
http://secunia.com/advisories/23455 cve-icon cve-icon
http://secunia.com/advisories/23680 cve-icon cve-icon
http://secunia.com/advisories/23794 cve-icon cve-icon
http://secunia.com/advisories/23841 cve-icon cve-icon
http://secunia.com/advisories/23915 cve-icon cve-icon
http://secunia.com/advisories/24099 cve-icon cve-icon
http://secunia.com/advisories/24930 cve-icon cve-icon
http://secunia.com/advisories/24950 cve-icon cve-icon
http://secunia.com/advisories/25284 cve-icon cve-icon
http://secunia.com/advisories/25399 cve-icon cve-icon
http://secunia.com/advisories/25649 cve-icon cve-icon
http://secunia.com/advisories/26329 cve-icon cve-icon
http://secunia.com/advisories/26893 cve-icon cve-icon
http://secunia.com/advisories/28115 cve-icon cve-icon
http://secunia.com/advisories/31492 cve-icon cve-icon
http://secunia.com/advisories/38567 cve-icon cve-icon
http://secunia.com/advisories/38568 cve-icon cve-icon
http://secunia.com/advisories/41818 cve-icon cve-icon
http://secunia.com/advisories/60799 cve-icon cve-icon
http://security.freebsd.org/advisories/FreeBSD-SA-06:19.openssl.asc cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200609-05.xml cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200609-18.xml cve-icon cve-icon
http://securitytracker.com/id?1016791 cve-icon cve-icon
http://securitytracker.com/id?1017522 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.566955 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.605306 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102656-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102657-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102686-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102696-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102722-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102744-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102759-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200708-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201247-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201534-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000148.1-1 cve-icon cve-icon
http://support.attachmate.com/techdocs/2127.html cve-icon cve-icon
http://support.attachmate.com/techdocs/2128.html cve-icon cve-icon
http://support.attachmate.com/techdocs/2137.html cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2006-188.htm cve-icon cve-icon
http://www.arkoon.fr/upload/alertes/40AK-2006-04-FR-1.1_SSL360_OPENSSL_RSA.pdf cve-icon cve-icon
http://www.bluecoat.com/support/knowledge/openSSL_RSA_Signature_forgery.html cve-icon cve-icon
http://www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_response09186a008077af1b.html cve-icon cve-icon
http://www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtml cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1174 cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200610-06.xml cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml cve-icon cve-icon
http://www.imc.org/ietf-openpgp/mail-archive/msg14307.html cve-icon cve-icon
http://www.kb.cert.org/vuls/id/845620 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:161 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:177 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:178 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:207 cve-icon cve-icon
http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/ cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2006_26_sr.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2006_55_ssl.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2006_61_opera.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_10_ibmjava.html cve-icon cve-icon
http://www.openbsd.org/errata.html cve-icon cve-icon
http://www.openoffice.org/security/cves/CVE-2006-4339.html cve-icon cve-icon
http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.018.html cve-icon cve-icon
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.029-bind.html cve-icon cve-icon
http://www.openssl.org/news/secadv_20060905.txt cve-icon cve-icon
http://www.opera.com/support/search/supsearch.dml?index=845 cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html cve-icon cve-icon
http://www.osvdb.org/28549 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0661.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0062.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0072.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0073.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0629.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/445231/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/445822/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/450327/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/456546/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/489739/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/19849 cve-icon cve-icon
http://www.securityfocus.com/bid/22083 cve-icon cve-icon
http://www.securityfocus.com/bid/28276 cve-icon cve-icon
http://www.serv-u.com/releasenotes/ cve-icon cve-icon
http://www.sybase.com/detail?id=1047991 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-339-1 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA06-333A.html cve-icon cve-icon
http://www.us.debian.org/security/2006/dsa-1173 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2008-0005.html cve-icon cve-icon
http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html cve-icon cve-icon
http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html cve-icon cve-icon
http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html cve-icon cve-icon
http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html cve-icon cve-icon
http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html cve-icon cve-icon
http://www.vmware.com/support/player/doc/releasenotes_player.html cve-icon cve-icon
http://www.vmware.com/support/player2/doc/releasenotes_player2.html cve-icon cve-icon
http://www.vmware.com/support/server/doc/releasenotes_server.html cve-icon cve-icon
http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html cve-icon cve-icon
http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html cve-icon cve-icon
http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html cve-icon cve-icon
http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3453 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3566 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3730 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3748 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3793 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3899 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3936 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4205 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4206 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4207 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4216 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4327 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4329 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4366 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4417 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4586 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4744 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4750 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/5146 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/0254 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/0343 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1401 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1815 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1945 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2163 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2315 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2783 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/4224 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0905/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0366 cve-icon cve-icon
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742 cve-icon cve-icon
http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3117 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/28755 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1633 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-616 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2006-4339 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11656 cve-icon cve-icon
https://secure-support.novell.com/KanisaPlatform/Publishing/41/3143224_f.SAL_Public.html cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2006-4339 cve-icon
https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144 cve-icon cve-icon
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.03797}

epss

{'score': 0.10187}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T19:06:07.378Z

Reserved: 2006-08-24T00:00:00.000Z

Link: CVE-2006-4339

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-09-05T17:04:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2006-4339

cve-icon Redhat

Severity : Important

Publid Date: 2006-09-05T00:00:00Z

Links: CVE-2006-4339 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses