verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade gnutlsUpgrade gnutls-devel | Dec 10, 2025 | Oct 2, 2006 |
| Gentoo Linux | — | Upgrade net-libs/gnutls. | Oct 30, 2017 | Sep 14, 2006 |
| Suse | — | Upgrade libgnutls26-32bitUpgrade gnutlsUpgrade libgnutls-extra-develUpgrade libgnutls30Upgrade libgnutls-devel-docUpgrade libgnutls-extra26Upgrade libgnutls-develUpgrade libgnutlsxx30Upgrade libgnutls26Upgrade libgnutls26-x86Upgrade libgnutlsxx-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libgnutls12Upgrade libgnutls11 | Nov 8, 2024 | Sep 14, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub