GNUTLS PKCS RSA Signature Forgery Vulnerability

Bugtraq ID: 20027
Class: Design Error
CVE: CVE-2006-4790
Remote: Yes
Local: No
Published: Sep 14 2006 12:00AM
Updated: Jun 29 2007 07:58PM
Credit: Daniel Bleichenbacher, Yutaka Oiwa, Kazukuni Kobara, and Hajime Watanabe are credited with the discovery of this vulnerability.
Vulnerable: Ubuntu Ubuntu Linux 5.10 sparc
Ubuntu Ubuntu Linux 5.10 powerpc
Ubuntu Ubuntu Linux 5.10 i386
Ubuntu Ubuntu Linux 5.10 amd64
Ubuntu Ubuntu Linux 5.0 4 powerpc
Ubuntu Ubuntu Linux 5.0 4 i386
Ubuntu Ubuntu Linux 5.0 4 amd64
Ubuntu Ubuntu Linux 6.06 LTS sparc
Ubuntu Ubuntu Linux 6.06 LTS powerpc
Ubuntu Ubuntu Linux 6.06 LTS i386
Ubuntu Ubuntu Linux 6.06 LTS amd64
Trustix Secure Linux 3.0
Trustix Secure Linux 2.2
Trustix Secure Enterprise Linux 2.0
SuSE SUSE Linux Enterprise Server SDK 9
SuSE SUSE Linux Enterprise Server 8
+ Linux kernel 2.4.21
+ Linux kernel 2.4.19
SuSE SUSE Linux Enterprise SDK 10
Sun Solaris 10.0_x86
Sun Solaris 10.0
S.u.S.E. UnitedLinux 1.0
S.u.S.E. SuSE Linux Standard Server 8.0
S.u.S.E. SuSE Linux School Server for i386
S.u.S.E. SUSE LINUX Retail Solution 8.0
S.u.S.E. Open-Enterprise-Server 9.0
S.u.S.E. Office Server
S.u.S.E. Novell Linux Desktop 9.0
S.u.S.E. Novell Linux Desktop 1.0
S.u.S.E. Linux Professional 10.0 OSS
S.u.S.E. Linux Professional 10.0
S.u.S.E. Linux Professional 9.3 x86_64
S.u.S.E. Linux Professional 9.3
S.u.S.E. Linux Professional 9.2 x86_64
S.u.S.E. Linux Professional 9.2
S.u.S.E. Linux Professional 9.1 x86_64
S.u.S.E. Linux Professional 9.1
S.u.S.E. Linux Professional 9.0 x86_64
S.u.S.E. Linux Professional 9.0
S.u.S.E. Linux Professional 10.1
S.u.S.E. Linux Personal 10.0 OSS
S.u.S.E. Linux Personal 9.3 x86_64
S.u.S.E. Linux Personal 9.3
S.u.S.E. Linux Personal 9.2 x86_64
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Personal 9.1 x86_64
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 10.1
S.u.S.E. Linux Openexchange Server
S.u.S.E. Linux Office Server
S.u.S.E. Linux Enterprise Server for S/390 9.0
S.u.S.E. Linux Enterprise Server for S/390
S.u.S.E. Linux Enterprise Server 9
S.u.S.E. Linux Enterprise Server 10
S.u.S.E. Linux Desktop 1.0
S.u.S.E. Linux Desktop 10
S.u.S.E. Linux Database Server 0
S.u.S.E. Linux Connectivity Server
RedHat Enterprise Linux WS 4
RedHat Enterprise Linux ES 4
RedHat Desktop 4.0
Red Hat Enterprise Linux AS 4
Mandriva Linux Mandrake 2006.0 x86_64
Mandriva Linux Mandrake 2006.0
MandrakeSoft Corporate Server 4.0 x86_64
MandrakeSoft Corporate Server 4.0
GNU GnuTLS 1.4.2
GNU GnuTLS 1.4
GNU GnuTLS 1.3.4
GNU GnuTLS 1.3.3
GNU GnuTLS 1.3.2
GNU GnuTLS 1.3.1
GNU GnuTLS 1.3
GNU GnuTLS 1.2.10
GNU GnuTLS 1.2.9
GNU GnuTLS 1.2.8
GNU GnuTLS 1.2.7
GNU GnuTLS 1.2.6
GNU GnuTLS 1.2.5
GNU GnuTLS 1.2.4
GNU GnuTLS 1.2.3
GNU GnuTLS 1.2.2
GNU GnuTLS 1.2.1
GNU GnuTLS 1.2
GNU GnuTLS 1.0.25
+ Red Hat Fedora Core4
GNU GnuTLS 1.0.17
GNU GnuTLS 1.0.16
GNU GnuTLS 1.0.15
GNU GnuTLS 1.0.14
GNU GnuTLS 1.0.9
GNU GnuTLS 1.0.8
GNU GnuTLS 1.0.7
GNU GnuTLS 1.0.6
GNU GnuTLS 1.0.5
GNU GnuTLS 1.0.4
GNU GnuTLS 1.0.3
GNU GnuTLS 1.0.2
GNU GnuTLS 1.0.1
GNU GnuTLS 1.0
Debian Linux 3.1 sparc
Debian Linux 3.1 s/390
Debian Linux 3.1 ppc
Debian Linux 3.1 mipsel
Debian Linux 3.1 mips
Debian Linux 3.1 m68k
Debian Linux 3.1 ia-64
Debian Linux 3.1 ia-32
Debian Linux 3.1 hppa
Debian Linux 3.1 arm
Debian Linux 3.1 amd64
Debian Linux 3.1 alpha
Debian Linux 3.1
Avaya Interactive Response 2.0
Not Vulnerable: GNU GnuTLS 1.4.3


 

Privacy Statement
Copyright 2010, SecurityFocus