PT-2009-6717 · Mozilla+3 · Network Security Services (Nss) Library+3

Dan Kaminsky

·

Publicado

1970-01-01

·

Atualizado

2024-03-12

·

CVE-2009-2409

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Network Security Services (NSS) library versions prior to 3.12.3 GnuTLS versions prior to 2.6.4 and 2.7.4 OpenSSL versions 0.9.8 through 0.9.8k
Description The issue allows remote attackers to potentially spoof certificates by exploiting MD2 design flaws to generate a hash collision in less than brute-force time. This could lead to violations of confidentiality, integrity, and availability of protected information. The scope of this issue is currently limited due to the large amount of computation required.
Recommendations For Network Security Services (NSS) library versions prior to 3.12.3, update to version 3.12.3 or later. For GnuTLS versions prior to 2.6.4 and 2.7.4, update to version 2.6.4 or 2.7.4 or later. For OpenSSL versions 0.9.8 through 0.9.8k, update to version 0.9.8l or later. As a temporary workaround, consider restricting the use of MD2 with X.509 certificates until a patch is available.

Exploit

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03443
BDU:2015-03444
BDU:2015-09404
CVE-2009-2409
DSA-1874-1
DSA-1888-1
DSA-1935-1
RHSA-2009:1184
RHSA-2009:1186
RHSA-2009:1190
RHSA-2009:1207
RHSA-2009:1432
RHSA-2009:1560
RHSA-2009:1571
RHSA-2009:1584
RHSA-2009:1662
RHSA-2009_1184
RHSA-2009_1186
RHSA-2009_1584
RHSA-2010:0054
RHSA-2010:0163
RHSA-2010:0166
RHSA-2010_0054
RHSA-2010_0163
RHSA-2010_0166
ROSA-SA-2024-2370

Produtos afetados

Gnutls
Network Security Services (Nss) Library
Openssl
Red Hat