PT-2009-6717 · Mozilla+3 · Network Security Services (Nss) Library+3

Dan Kaminsky

·

Published

1970-01-01

·

Updated

2024-03-12

·

CVE-2009-2409

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Network Security Services (NSS) library versions prior to 3.12.3 GnuTLS versions prior to 2.6.4 and 2.7.4 OpenSSL versions 0.9.8 through 0.9.8k
Description The issue allows remote attackers to potentially spoof certificates by exploiting MD2 design flaws to generate a hash collision in less than brute-force time. This could lead to violations of confidentiality, integrity, and availability of protected information. The scope of this issue is currently limited due to the large amount of computation required.
Recommendations For Network Security Services (NSS) library versions prior to 3.12.3, update to version 3.12.3 or later. For GnuTLS versions prior to 2.6.4 and 2.7.4, update to version 2.6.4 or 2.7.4 or later. For OpenSSL versions 0.9.8 through 0.9.8k, update to version 0.9.8l or later. As a temporary workaround, consider restricting the use of MD2 with X.509 certificates until a patch is available.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03443
BDU:2015-03444
BDU:2015-09404
CVE-2009-2409
DSA-1874-1
DSA-1888-1
DSA-1935-1
RHSA-2009:1184
RHSA-2009:1186
RHSA-2009:1190
RHSA-2009:1207
RHSA-2009:1432
RHSA-2009:1560
RHSA-2009:1571
RHSA-2009:1584
RHSA-2009:1662
RHSA-2009_1184
RHSA-2009_1186
RHSA-2009_1584
RHSA-2010:0054
RHSA-2010:0163
RHSA-2010:0166
RHSA-2010_0054
RHSA-2010_0163
RHSA-2010_0166
ROSA-SA-2024-2370

Affected Products

Gnutls
Network Security Services (Nss) Library
Openssl
Red Hat