MD5: MD5 Message-Digest Algorithm is not collision resistant
Published Jan 5, 2009
9.8
CRITICALCVSS 3.1
EPSS 9.93%
Description
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.
Affected products
No data.
Running on/with
- n/a
No data.
Red Hat Certificate System 7.3
rhpki-ca-0:7.3.0-21.el4
Fixed · RHSA-2010:0837
Red Hat Certificate System 7.3
rhpki-common-0:7.3.0-41.el4
Fixed · RHSA-2010:0837
Red Hat Certificate System 7.3
rhpki-util-0:7.3.0-21.el4
Fixed · RHSA-2010:0837
Red Hat Certificate System 8
pki-ca-0:8.0.7-1.el5pki
Fixed · RHSA-2010:0838
Red Hat Certificate System 8
pki-common-0:8.0.6-2.el5pki
Fixed · RHSA-2010:0838
Red Hat Certificate System 8
pki-util-0:8.0.5-1.el5pki
Fixed · RHSA-2010:0838
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Certificate System 7.3 | rhpki-ca-0:7.3.0-21.el4 | Fixed | RHSA-2010:0837 |
| Red Hat Certificate System 7.3 | rhpki-common-0:7.3.0-41.el4 | Fixed | RHSA-2010:0837 |
| Red Hat Certificate System 7.3 | rhpki-util-0:7.3.0-21.el4 | Fixed | RHSA-2010:0837 |
| Red Hat Certificate System 8 | pki-ca-0:8.0.7-1.el5pki | Fixed | RHSA-2010:0838 |
| Red Hat Certificate System 8 | pki-common-0:8.0.6-2.el5pki | Fixed | RHSA-2010:0838 |
| Red Hat Certificate System 8 | pki-util-0:8.0.5-1.el5pki | Fixed | RHSA-2010:0838 |
No package ranges for this CVE.
Remediation
Red Hat statement
Please see https://access.redhat.com/solutions/15378
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed May 28, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (24 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.93% (0.09934) | 95.45th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.85% (0.09854) | 94.94th | v5 (v2026.06.15) |
| May 29, 2026 | 8.25% (0.08251) | 92.35th | v4 (v2025.03.14) |
| Jan 19, 2026 | 6.23% (0.06226) | 90.59th | v4 (v2025.03.14) |
| Dec 27, 2025 | 8.46% (0.08455) | 92.07th | v4 (v2025.03.14) |
| Dec 18, 2025 | 11.12% (0.11116) | 93.22th | v4 (v2025.03.14) |
| Oct 7, 2025 | 9.47% (0.09468) | 92.51th | v4 (v2025.03.14) |
| Apr 16, 2025 | 10.73% (0.10729) | 92.87th | v4 (v2025.03.14) |
| Mar 30, 2025 | 8.15% (0.08150) | 91.37th | v4 (v2025.03.14) |
| Mar 29, 2025 | 17.01% (0.17011) | 91.69th | v4 (v2025.03.14) |
| Mar 28, 2025 | 8.15% (0.08150) | 91.38th | v4 (v2025.03.14) |
| Mar 27, 2025 | 17.01% (0.17011) | 94.10th | v4 (v2025.03.14) |
| Mar 20, 2025 | 8.15% (0.08150) | 91.47th | v4 (v2025.03.14) |
| Mar 19, 2025 | 17.01% (0.17011) | 94.21th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.96% (0.06959) | 90.76th | v4 (v2025.03.14) |
| Feb 17, 2025 | 8.76% (0.08755) | 94.64th | v3 (v2023.03.01) |
| Dec 17, 2024 | 7.29% (0.07286) | 94.00th | v3 (v2023.03.01) |
| Jul 16, 2024 | 1.11% (0.01106) | 84.63th | v3 (v2023.03.01) |
| Jun 10, 2024 | 1.18% (0.01184) | 85.06th | v3 (v2023.03.01) |
| May 2, 2024 | 1.22% (0.01224) | 85.20th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.22% (0.01224) | 83.19th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.57% (0.12567) | 95.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.57% (0.12567) | 95.18th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.57% (0.12567) | 90.03th | v2 (v2022.01.01) |
References (29)
- http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/ x_refsource_MISC
- http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx x_refsource_MISC
- http://secunia.com/advisories/33826 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34281 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42181 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/4866 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1024697 vdb-entryx_refsource_SECTRACK
- http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html vendor-advisoryx_refsource_CISCO
- http://www.doxpara.com/research/md5/md5_someday.pdf x_refsource_MISC
- http://www.kb.cert.org/vuls/id/836068 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.microsoft.com/technet/security/advisory/961509.mspx x_refsource_MISCMitigationPatchVendor Advisory
- http://www.phreedom.org/research/rogue-ca/ x_refsource_MISC
- http://www.securityfocus.com/archive/1/499685/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/33065 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-740-1 vendor-advisoryx_refsource_UBUNTU
- http://www.win.tue.nl/hashclash/SoftIntCodeSign/ x_refsource_MISC
- http://www.win.tue.nl/hashclash/rogue-ca/ x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2004-2761 Vendor Advisory
- https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=648886 x_refsource_CONFIRMIssue Tracking
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935 x_refsource_CONFIRM
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888 x_refsource_CONFIRM
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2004-2761
- https://rhn.redhat.com/errata/RHSA-2010-0837.html vendor-advisoryx_refsource_REDHAT
- https://rhn.redhat.com/errata/RHSA-2010-0838.html vendor-advisoryx_refsource_REDHAT
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03814en_us x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2004-2761
- https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00096.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.