CVE-2006-5201: Medium severity sun secure global desktop vulnerability
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.212, and SDK and JRE 1.3.x up to 1.3.119; (3) JSSE 1.0.303 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5201?
CVE-2006-5201 has a CVSS score that indicates a moderate level of severity depending on the specific configuration and use case.
How do I fix CVE-2006-5201?
To fix CVE-2006-5201, ensure you upgrade to the latest versions of all affected software packages identified in the vulnerability report.
Which versions are affected by CVE-2006-5201?
CVE-2006-5201 affects multiple versions of Java JDK, JRE, NSS, JSSE, and other Sun Solaris packages.
What types of software are vulnerable in CVE-2006-5201?
CVE-2006-5201 affects various Sun Solaris software packages, including NSS, Java JDK/JRE, JSSE, and StarOffice.
Can CVE-2006-5201 be exploited remotely?
Yes, CVE-2006-5201 has the potential for remote exploitation, which can compromise the integrity of systems using vulnerable software.