---
title: "CVE-2006-5462\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-5462?format=md
keywords: index, follow
---

# CVE-2006-5462

Publication date 8 November 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Mozilla Network Security Service (NSS) library before 3.11.3, as used in
Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey
before 1.0.6, when using an RSA key with exponent 3, does not properly
handle extra data in a signature, which allows remote attackers to forge
signatures for SSL/TLS and email certificates. NOTE: this identifier is for
unpatched product versions that were originally intended to be addressed by
CVE-2006-4340.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 7.04 feisty | Not affected |
| 6.10 edgy | Not affected |
| 6.06 LTS dapper | Fixed 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1 |
| mozilla-thunderbird | 7.04 feisty | Fixed 1.5.0.13-0ubuntu0.7.04 |
| 6.10 edgy | Fixed 1.5.0.13-0ubuntu0.6.10 |
| 6.06 LTS dapper | Fixed 1.5.0.13-0ubuntu0.6.06 |
| xulrunner | 7.04 feisty | Fixed 1.8.0.10-3ubuntu1 |
| 6.10 edgy | Ignored end of life, was needed |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5462)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-5462)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-5462)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-5462)

### Related Ubuntu Security Notices (USN)

+ [USN-382-1](https://usn.ubuntu.com/USN-382-1)
+ Thunderbird vulnerabilities
+ 21 November 2006

+ [USN-381-1](https://usn.ubuntu.com/USN-381-1)
+ Firefox vulnerabilities
+ 21 November 2006

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-5462>
