Title : GnuTLS RSA Key Handling PKCS #1 v1.5 Security Bypass and Signature Forgery VUPEN ID : VUPEN/ADV-2006-3635 CVE ID : CVE-2006-4790
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-09-15
Technical Description
A vulnerability has been identified in GnuTLS, which could be exploited by attackers to bypass security restrictions. This flaw is due to an error when handling and verifying RSA keys with exponent 3, which could be exploited by attackers to forge PKCS #1 v1.5 signatures and bypass security verifications.