VDB

DEBIAN-CVE-2006-4339

DEBIAN-CVE-2006-4339 PUBLISHED

OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.

Affected Products

VendorProductVersions
Debian:11openssl0, 0, 0
Debian:13openssl0, 0, 0
Debian:12openssl0, 0, 0
Debian:14openssl0, 0, 0

Timeline

  • Sep 5, 2006 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›