MEDIUM · 4.0

CVE-2006-5201

Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlie...

Vulnerability Description

Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.

CVSS Score

4.0

MEDIUM

AV:N/AC:H/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SunNssAll versions
SunSecure Global DesktopAll versions
SunStarofficeAll versions
SunSolaris9.0
SunSunos5.8
SunJdk1.5.0
SunJre1.3.1
SunSdk1.3.1
SunJsse1.0.3

References

FAQ

What is CVE-2006-5201?

CVE-2006-5201 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlie...

How severe is CVE-2006-5201?

CVE-2006-5201 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-5201?

Check the references section above for vendor advisories and patch information. Affected products include: Sun Nss, Sun Secure Global Desktop, Sun Staroffice, Sun Solaris, Sun Sunos.