The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.
References
Link Resource
http://www.cits.rub.de/MD5Collisions/ Broken Link
http://www.ubuntu.com/usn/usn-179-1 Vendor Advisory
https://bugzilla.ubuntu.com/show_bug.cgi?id=13593 Broken Link Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2005-09-16T04:00:00

Updated: 2009-01-07T10:00:00

Reserved: 2005-09-16T00:00:00


Link: CVE-2005-2946

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2005-09-16T22:03:00.000

Modified: 2024-02-09T03:13:55.780


Link: CVE-2005-2946

JSON object: View

cve-icon Redhat Information

No data.

CWE