CVE-2004-2761: Critical severity IETF Md5 vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2004-2761 to the following vulnerability:
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.
References: http://www.kb.cert.org/vuls/id/836068 http://eprint.iacr.org/2004/199 http://eprint.iacr.org/2005/067 http://www.win.tue.nl/hashclash/rogue-ca/ http://www.phreedom.org/research/rogue-ca/ http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2004-2761?
CVE-2004-2761 is classified as a high severity vulnerability due to its potential to allow spoofing attacks.
How do I fix CVE-2004-2761?
To mitigate CVE-2004-2761, upgrade to the latest versions of affected packages such as rhpki-ca 0:7.3.0-21.el4 or pki-ca 0:8.0.7-1.el5.
What software is affected by CVE-2004-2761?
Affected software includes various Red Hat packages such as rhpki-ca, rhpki-common, and pki-ca.
What does CVE-2004-2761 exploit?
CVE-2004-2761 exploits the collision resistance weakness of the MD5 Message-Digest Algorithm.
Can CVE-2004-2761 affect X.509 certificates?
Yes, CVE-2004-2761 can significantly affect the integrity of X.509 certificates by making them vulnerable to spoofing.