Upstream information
Description
verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.NVD CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 206636 SUSE Security Advisories:- SUSE-SA:2007:010, published Thu, 18 Jan 2007 14:00:00 +0000
- SUSE-SR:2006:023, published Wed, 27 Sep 2006 14:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| Novell Linux Desktop 9 for x86 Novell Linux Desktop 9 for x86_64 Open Enterprise Server |
| Builds YOU Patch Nr: 11228 ZYPP Patch Nr: 2117 |
| SUSE LINUX Retail Solution 8 SuSE Linux Openexchange Server 4 SuSE Linux School Server for i386 SuSE Linux Standard Server 8 UnitedLinux 1.0 |
| slrs8.x86 |
| SUSE LINUX 10.0 |
| |
| SUSE LINUX 10.1 |
| |
| SUSE LINUX 9.2 |
| |
| SUSE LINUX 9.3 |
| |
| Open Enterprise Server |
| core9.s390 core9.x86 YOU Patch Nr: 11388 |
