CVE-2005-2946

Publication date 16 September 2005

Last updated 17 July 2025


Ubuntu priority

Cvss 3 Severity Score

7.5 · High

Score breakdown

Description

The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

Status

Package Ubuntu Release Status
openssl 7.04 feisty
Fixed 0.9.8b-2ubuntu2
6.10 edgy
Fixed 0.9.8b-2ubuntu2
6.06 LTS dapper
Fixed 0.9.8a-7ubuntu0.3

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.5 · High

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N


Access our resources on patching vulnerabilities