Mandriva Linux Security Advisory MDKSA-2006-161 – Daniel Bleichenbacher recently described an attack on PKCS #1 version 1.5 signatures where an RSA key with a small exponent used could be vulnerable to forgery of a PKCS #1 version 1.5 signature signed by that key. Any software using OpenSSL to verify X.509 certificates is potentially vulnerable to this issue, as well as any other use of PKCS #1 version 1.5, including software uses OpenSSL for SSL or TLS.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/49782/MDKSA-2006-161.txt
Source: https://packetstormsecurity.com/files/49782/Mandriva-Linux-Security-Advisory-2006.161.html