Vulnerability Database

296,172

Total vulnerabilities in the database

CVE-2006-4790

verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.

  • Published: Sep 14, 2006
  • Updated: Apr 13, 2023
  • CVE: CVE-2006-4790
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:P/A:N

No CWE or OWASP classifications available.

Software From Fixed in
gnu / gnutls 1.2.8 1.2.8.x
gnu / gnutls 1.1.14 1.1.14.x
gnu / gnutls 1.4.1 1.4.1.x
gnu / gnutls 1.2.11 1.2.11.x
gnu / gnutls 1.1.21 1.1.21.x
gnu / gnutls 1.0.20 1.0.20.x
gnu / gnutls 1.2.5 1.2.5.x
gnu / gnutls 1.0.17 1.0.17.x
gnu / gnutls 1.2.4 1.2.4.x
gnu / gnutls 1.3.1 1.3.1.x
gnu / gnutls 1.0.24 1.0.24.x
gnu / gnutls 1.0.21 1.0.21.x
gnu / gnutls 1.1.20 1.1.20.x
gnu / gnutls 1.2.10 1.2.10.x
gnu / gnutls 1.1.22 1.1.22.x
gnu / gnutls 1.4.0 1.4.0.x
gnu / gnutls 1.3.4 1.3.4.x
gnu / gnutls 1.0.19 1.0.19.x
gnu / gnutls 1.2.1 1.2.1.x
gnu / gnutls 1.1.19 1.1.19.x
gnu / gnutls 1.1.18 1.1.18.x
gnu / gnutls 1.2.8.1a1 1.2.8.1a1.x
gnu / gnutls 1.2.2 1.2.2.x
gnu / gnutls 1.2.0 1.2.0.x
gnu / gnutls 1.0.18 1.0.18.x
gnu / gnutls 1.2.7 1.2.7.x
gnu / gnutls 1.3.2 1.3.2.x
gnu / gnutls 1.0.25 1.0.25.x
gnu / gnutls 1.1.15 1.1.15.x
gnu / gnutls 1.0.23 1.0.23.x
gnu / gnutls 1.3.0 1.3.0.x
gnu / gnutls 1.3.5 1.3.5.x
gnu / gnutls 1.1.23 1.1.23.x
gnu / gnutls 1.2.3 1.2.3.x
gnu / gnutls 1.2.6 1.2.6.x
gnu / gnutls 1.2.9 1.2.9.x
gnu / gnutls 1.1.16 1.1.16.x
gnu / gnutls 1.0.22 1.0.22.x
gnu / gnutls 1.1.17 1.1.17.x
gnu / gnutls 1.3.3 1.3.3.x