PT-2009-6717 · Mozilla+3 · Network Security Services (Nss) Library+3
Dan Kaminsky
·
Published
1970-01-01
·
Updated
2024-03-12
·
CVE-2009-2409
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Network Security Services (NSS) library versions prior to 3.12.3
GnuTLS versions prior to 2.6.4 and 2.7.4
OpenSSL versions 0.9.8 through 0.9.8k
Description
The issue allows remote attackers to potentially spoof certificates by exploiting MD2 design flaws to generate a hash collision in less than brute-force time. This could lead to violations of confidentiality, integrity, and availability of protected information. The scope of this issue is currently limited due to the large amount of computation required.
Recommendations
For Network Security Services (NSS) library versions prior to 3.12.3, update to version 3.12.3 or later.
For GnuTLS versions prior to 2.6.4 and 2.7.4, update to version 2.6.4 or 2.7.4 or later.
For OpenSSL versions 0.9.8 through 0.9.8k, update to version 0.9.8l or later.
As a temporary workaround, consider restricting the use of MD2 with X.509 certificates until a patch is available.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gnutls
Network Security Services (Nss) Library
Openssl
Red Hat