PT-2009-6717 · Mozilla+3 · Network Security Services (Nss) Library+3
Dan Kaminsky
·
Publicado
1970-01-01
·
Atualizado
2024-03-12
·
CVE-2009-2409
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Network Security Services (NSS) library versions prior to 3.12.3
GnuTLS versions prior to 2.6.4 and 2.7.4
OpenSSL versions 0.9.8 through 0.9.8k
Description
The issue allows remote attackers to potentially spoof certificates by exploiting MD2 design flaws to generate a hash collision in less than brute-force time. This could lead to violations of confidentiality, integrity, and availability of protected information. The scope of this issue is currently limited due to the large amount of computation required.
Recommendations
For Network Security Services (NSS) library versions prior to 3.12.3, update to version 3.12.3 or later.
For GnuTLS versions prior to 2.6.4 and 2.7.4, update to version 2.6.4 or 2.7.4 or later.
For OpenSSL versions 0.9.8 through 0.9.8k, update to version 0.9.8l or later.
As a temporary workaround, consider restricting the use of MD2 with X.509 certificates until a patch is available.
Exploit
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gnutls
Network Security Services (Nss) Library
Openssl
Red Hat