Common Vulnerabilities and Exposures assigned an identifier CVE-2004-2761 to the following vulnerability:
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.
References: http://www.kb.cert.org/vuls/id/836068 http://eprint.iacr.org/2004/199 http://eprint.iacr.org/2005/067 http://www.win.tue.nl/hashclash/rogue-ca/ http://www.phreedom.org/research/rogue-ca/ http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/