CVE-2005-2946 PUBLISHED CVSS 7.5 HIGH

The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

EPSS 0.19% · 40.7th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.19%
40.7th percentile

Affected Products

VendorProductVersions
canonicalubuntu_linux4.10, 5.04
opensslopenssl0
n/an/an/a

Timeline

References

Open in Interactive Console →