CVE-2006-4790 describes a vulnerability in GnuTLS versions prior to 1.4.4, specifically when using RSA keys with exponent 3. This flaw allows remote attackers to forge PKCS #1 v1.5 signatures by manipulating excess data in the digestAlgorithm.parameters field, leading to incorrect verification of X.509 and other certificates. The vulnerability has a CVSS score of 5.0, indicating a network-based attack with low complexity, resulting in a partial integrity impact. There is no evidence of active exploitation, public exploit code, or significant community discussion, with only one mention and one media article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.17CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.17:*:*:*:*:*:*:* | ||
1.0.18CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.18:*:*:*:*:*:*:* | ||
1.0.19CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.19:*:*:*:*:*:*:* | ||
1.0.20CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.20:*:*:*:*:*:*:* | ||
1.0.21CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.21:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.