Executive Summary
Summary | |
---|---|
Title | Sun Alert 200196 Security Vulnerability in RSA Signature Verification Impacting Multiple SUN Products |
Informations | |||
---|---|---|---|
Name | SUN-200196 | First vendor Publication | 2009-10-13 |
Vendor | Sun | Last vendor Modification | 2010-01-25 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Product: Mozilla 1.4 for Solaris, Sun Java System Application Server 9.1, Solaris 10, Sun Secure Global Desktop Software 4.5, StarOffice 9 Software, Sun Java Enterprise System 7 Certain Sun products (including some bundled third party products) may be vulnerable to an RSA(1) Signature Verification vulnerability that allows unauthorized forged certificates to be validated. This may result in a number of different types of remote exploits. The specific impact will vary from product to product. Please see the "Contributing Factors" section for further details. More details of the issue are available from CERT Vulnerability VU#845620 at http://www.security-database.com/detail.php?vu=VU845620 which is also mentioned at http://www.security-database.com/detail.php?cve=CVE-2006-4339 State: Preliminary First released: 13-Oct-2009 |
Original Source
Url : http://blogs.sun.com/security/entry/sun_alert_200196 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-96 | Block Access to Libraries |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-310 | Cryptographic Issues |
OVAL Definitions
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2010-03-16 | Name : FreeBSD Ports: openoffice.org File : nvt/freebsd_openoffice.org.nasl |
2010-02-03 | Name : Solaris Update for Kernel 122300-48 File : nvt/gb_solaris_122300_48.nasl |
2010-02-03 | Name : Solaris Update for Kernel 122301-48 File : nvt/gb_solaris_122301_48.nasl |
2009-11-17 | Name : Mac OS X Version File : nvt/macosx_version.nasl |
2009-10-13 | Name : Solaris Update for Kernel 122300-44 File : nvt/gb_solaris_122300_44.nasl |
2009-10-13 | Name : Solaris Update for /usr/bin/ssh 114357-18 File : nvt/gb_solaris_114357_18.nasl |
2009-10-13 | Name : Solaris Update for /usr/bin/ssh 114356-19 File : nvt/gb_solaris_114356_19.nasl |
2009-10-13 | Name : Solaris Update for Kernel 122301-44 File : nvt/gb_solaris_122301_44.nasl |
2009-10-13 | Name : Solaris Update for pkg utilities 113713-28 File : nvt/gb_solaris_113713_28.nasl |
2009-10-10 | Name : SLES9: Security update for openssl File : nvt/sles9p5020640.nasl |
2009-10-10 | Name : SLES9: Security update for bind File : nvt/sles9p5015338.nasl |
2009-09-23 | Name : Solaris Update for Kernel 122301-42 File : nvt/gb_solaris_122301_42.nasl |
2009-09-23 | Name : Solaris Update for pkg utilities 114568-27 File : nvt/gb_solaris_114568_27.nasl |
2009-06-03 | Name : Solaris Update for wanboot 122715-02 File : nvt/gb_solaris_122715_02.nasl |
2009-06-03 | Name : Solaris Update for bootconfchk 123376-01 File : nvt/gb_solaris_123376_01.nasl |
2009-06-03 | Name : Solaris Update for bootconfchk 123377-01 File : nvt/gb_solaris_123377_01.nasl |
2009-06-03 | Name : Solaris Update for kernel 127127-11 File : nvt/gb_solaris_127127_11.nasl |
2009-06-03 | Name : Solaris Update for Kernel 122301-40 File : nvt/gb_solaris_122301_40.nasl |
2009-06-03 | Name : Solaris Update for kernel 127128-11 File : nvt/gb_solaris_127128_11.nasl |
2009-06-03 | Name : Solaris Update for kernel 120011-14 File : nvt/gb_solaris_120011_14.nasl |
2009-06-03 | Name : Solaris Update for Kernel 122300-40 File : nvt/gb_solaris_122300_40.nasl |
2009-06-03 | Name : Solaris Update for wanboot 117123-08 File : nvt/gb_solaris_117123_08.nasl |
2009-06-03 | Name : Solaris Update for pkg utilities 114568-26 File : nvt/gb_solaris_114568_26.nasl |
2009-06-03 | Name : Solaris Update for /usr/bin/ssh 114357-17 File : nvt/gb_solaris_114357_17.nasl |
2009-06-03 | Name : Solaris Update for /usr/bin/ssh 114356-18 File : nvt/gb_solaris_114356_18.nasl |
2009-06-03 | Name : Solaris Update for NSPR 4.1.6 / NSS 3.3.4.8 114049-14 File : nvt/gb_solaris_114049_14.nasl |
2009-06-03 | Name : Solaris Update for pkg utilities 113713-27 File : nvt/gb_solaris_113713_27.nasl |
2009-05-05 | Name : HP-UX Update for BIND HPSBUX02219 File : nvt/gb_hp_ux_HPSBUX02219.nasl |
2009-05-05 | Name : HP-UX Update for Apache Remote Execution of Arbitrary Code HPSBUX02186 File : nvt/gb_hp_ux_HPSBUX02186.nasl |
2009-01-28 | Name : SuSE Update for IBMJava2 SUSE-SA:2007:010 File : nvt/gb_suse_2007_010.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200610-06 (nss) File : nvt/glsa_200610_06.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200609-18 (opera) File : nvt/glsa_200609_18.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200609-05 (openssl) File : nvt/glsa_200609_05.nasl |
2008-09-04 | Name : FreeBSD Security Advisory (FreeBSD-SA-06:19.openssl.asc) File : nvt/freebsdsa_openssl3.nasl |
2008-09-04 | Name : FreeBSD Ports: openssl File : nvt/freebsd_openssl1.nasl |
2008-09-04 | Name : FreeBSD Ports: opera, opera-devel, linux-opera File : nvt/freebsd_opera2.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1173-1 (openssl) File : nvt/deb_1173_1.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1174-1 (openssl096) File : nvt/deb_1174_1.nasl |
0000-00-00 | Name : Slackware Advisory SSA:2006-310-01 bind File : nvt/esoft_slk_ssa_2006_310_01.nasl |
0000-00-00 | Name : Slackware Advisory SSA:2006-257-02 openssl File : nvt/esoft_slk_ssa_2006_257_02.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
28549 | OpenSSL RSA Key PKCS #1 v1.5 Signature Forgery OpenSSL contains a flaw that may allow a malicious user to bypass certain security restrictions. The issue is triggered due to an error within the verification of certain signatures, if an RSA key with exponent 3 is used it may be possible to forge a PKCS #1 v1.5 signature signed by that key. It is possible that the flaw may allow bypassing security restrictions resulting in a loss of integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-10-10 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL6623.nasl - Type : ACT_GATHER_INFO |
2014-09-01 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201408-19.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing a security update. File : oraclelinux_ELSA-2006-0661.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0073.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0062.nasl - Type : ACT_GATHER_INFO |
2012-01-04 | Name : The SSL layer on the remote server does not properly verify signatures. File : openssl_0_9_7k_0_9_8c.nasl - Type : ACT_GATHER_INFO |
2011-05-28 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2006-310-01.nasl - Type : ACT_GATHER_INFO |
2010-03-01 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_c97d7a37223311df96dd001b2134ef46.nasl - Type : ACT_GATHER_INFO |
2010-02-12 | Name : The remote Windows host has a program affected by multiple buffer overflows. File : openoffice_32.nasl - Type : ACT_GATHER_INFO |
2010-01-10 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2008-0264.nasl - Type : ACT_GATHER_INFO |
2010-01-10 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2008-0525.nasl - Type : ACT_GATHER_INFO |
2010-01-10 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2008-0629.nasl - Type : ACT_GATHER_INFO |
2008-04-02 | Name : The remote Windows host has an application that is affected by multiple issues. File : vmware_multiple_vmsa_2008_0005.nasl - Type : ACT_GATHER_INFO |
2007-12-17 | Name : The remote host is affected by multiple vulnerabilities. File : macosx_java_rel6.nasl - Type : ACT_GATHER_INFO |
2007-12-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_bind-2268.nasl - Type : ACT_GATHER_INFO |
2007-12-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_compat-openssl097g-2163.nasl - Type : ACT_GATHER_INFO |
2007-12-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_openssl-2082.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-339-1.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_compat-openssl097g-2171.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_opera-2181.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_openssl-2069.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_bind-2269.nasl - Type : ACT_GATHER_INFO |
2007-10-12 | Name : The remote host is missing Sun Security Patch number 122715-03 File : solaris9_x86_122715.nasl - Type : ACT_GATHER_INFO |
2007-09-25 | Name : The remote host is missing Sun Security Patch number 117123-10 File : solaris9_117123.nasl - Type : ACT_GATHER_INFO |
2007-09-25 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHNE_35920.nasl - Type : ACT_GATHER_INFO |
2007-02-18 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2006-178.nasl - Type : ACT_GATHER_INFO |
2007-02-18 | Name : The remote host is missing a vendor-supplied security patch File : suse_SA_2006_061.nasl - Type : ACT_GATHER_INFO |
2007-02-18 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2006-207.nasl - Type : ACT_GATHER_INFO |
2007-02-18 | Name : The remote host is missing a vendor-supplied security patch File : suse_SA_2006_055.nasl - Type : ACT_GATHER_INFO |
2007-02-18 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2006-166.nasl - Type : ACT_GATHER_INFO |
2007-02-18 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2006-177.nasl - Type : ACT_GATHER_INFO |
2007-02-09 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0072.nasl - Type : ACT_GATHER_INFO |
2007-01-17 | Name : The remote Fedora Core host is missing one or more security updates. File : fedora_2006-953.nasl - Type : ACT_GATHER_INFO |
2007-01-17 | Name : The remote Fedora Core host is missing a security update. File : fedora_2006-1004.nasl - Type : ACT_GATHER_INFO |
2006-12-30 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_077c2dca8f9a11dbab33000e0c2e438a.nasl - Type : ACT_GATHER_INFO |
2006-12-16 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2006-161.nasl - Type : ACT_GATHER_INFO |
2006-11-22 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35460.nasl - Type : ACT_GATHER_INFO |
2006-11-22 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35110.nasl - Type : ACT_GATHER_INFO |
2006-11-22 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35111.nasl - Type : ACT_GATHER_INFO |
2006-11-22 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35436.nasl - Type : ACT_GATHER_INFO |
2006-11-22 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35437.nasl - Type : ACT_GATHER_INFO |
2006-11-22 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35458.nasl - Type : ACT_GATHER_INFO |
2006-11-22 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35459.nasl - Type : ACT_GATHER_INFO |
2006-11-22 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35461.nasl - Type : ACT_GATHER_INFO |
2006-11-22 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35462.nasl - Type : ACT_GATHER_INFO |
2006-11-22 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35463.nasl - Type : ACT_GATHER_INFO |
2006-11-22 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35480.nasl - Type : ACT_GATHER_INFO |
2006-11-22 | Name : The remote HP-UX host is missing a security-related patch. File : hpux_PHSS_35481.nasl - Type : ACT_GATHER_INFO |
2006-11-06 | Name : The remote host is missing Sun Security Patch number 116648-25 File : solaris10_116648.nasl - Type : ACT_GATHER_INFO |
2006-11-06 | Name : The remote host is missing Sun Security Patch number 114045-14 File : solaris8_114045.nasl - Type : ACT_GATHER_INFO |
2006-11-06 | Name : The remote host is missing Sun Security Patch number 116648-25 File : solaris8_116648.nasl - Type : ACT_GATHER_INFO |
2006-11-06 | Name : The remote host is missing Sun Security Patch number 119209-36 File : solaris8_119209.nasl - Type : ACT_GATHER_INFO |
2006-11-06 | Name : The remote host is missing Sun Security Patch number 116648-25 File : solaris9_116648.nasl - Type : ACT_GATHER_INFO |
2006-10-20 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200610-06.nasl - Type : ACT_GATHER_INFO |
2006-10-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1173.nasl - Type : ACT_GATHER_INFO |
2006-10-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1174.nasl - Type : ACT_GATHER_INFO |
2006-09-22 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_1fe734bf4a0611dbb48d00508d6a62df.nasl - Type : ACT_GATHER_INFO |
2006-09-15 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2006-257-02.nasl - Type : ACT_GATHER_INFO |
2006-09-12 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2006-0661.nasl - Type : ACT_GATHER_INFO |
2006-09-12 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200609-05.nasl - Type : ACT_GATHER_INFO |
2006-09-12 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2006-0661.nasl - Type : ACT_GATHER_INFO |
2005-10-19 | Name : The remote host is missing Sun Security Patch number 119214-36 File : solaris10_x86_119214.nasl - Type : ACT_GATHER_INFO |
2005-10-19 | Name : The remote host is missing Sun Security Patch number 119213-36 File : solaris10_119213.nasl - Type : ACT_GATHER_INFO |
2005-10-05 | Name : The remote host is missing Sun Security Patch number 119212-36 File : solaris9_x86_119212.nasl - Type : ACT_GATHER_INFO |
2005-10-05 | Name : The remote host is missing Sun Security Patch number 119211-36 File : solaris9_119211.nasl - Type : ACT_GATHER_INFO |
2004-07-12 | Name : The remote host is missing Sun Security Patch number 114050-14 File : solaris9_x86_114050.nasl - Type : ACT_GATHER_INFO |
2004-07-12 | Name : The remote host is missing Sun Security Patch number 114049-14 File : solaris9_114049.nasl - Type : ACT_GATHER_INFO |