---
title: "CVE-2006-4340\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-4340?format=md
keywords: index, follow
---

# CVE-2006-4340

Publication date 15 September 2006

Last updated 4 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Mozilla Network Security Service (NSS) library before 3.11.3, as used in
Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey
before 1.0.5, when using an RSA key with exponent 3, does not properly
handle extra data in a signature, which allows remote attackers to forge
signatures for SSL/TLS and email certificates, a similar vulnerability to
CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating
that these versions were not completely patched by MFSA2006-60. The newer
fixes for 1.5.0.7 are covered by CVE-2006-5462.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 7.04 feisty | Not affected |
| 6.10 edgy | Not affected |
| 6.06 LTS dapper | Fixed 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1 |
| firefox-granparadiso | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| lightning-sunbird | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| midbrowser | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| mozilla-thunderbird | 7.04 feisty | Fixed 1.5.0.13-0ubuntu0.7.04 |
| 6.10 edgy | Fixed 1.5.0.13-0ubuntu0.6.10 |
| 6.06 LTS dapper | Fixed 1.5.0.13-0ubuntu0.6.06 |
| xulrunner | 7.04 feisty | Fixed 1.8.0.10-3ubuntu1 |
| 6.10 edgy | Ignored end of life, was needed |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4340)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-4340)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-4340)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-4340)

### Related Ubuntu Security Notices (USN)

+ [USN-351-1](https://usn.ubuntu.com/USN-351-1)
+ firefox vulnerabilities
+ 23 September 2006

+ [USN-361-1](https://usn.ubuntu.com/USN-361-1)
+ Mozilla vulnerabilities
+ 10 October 2006

+ [USN-350-1](https://usn.ubuntu.com/USN-350-1)
+ Thunderbird vulnerabilities
+ 22 September 2006

+ [USN-352-1](https://usn.ubuntu.com/USN-352-1)
+ Thunderbird vulnerabilities
+ 25 September 2006

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-4340>
