CVE Vulnerabilities

CVE-2009-1417

Published: Apr 30, 2009 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW

gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to successfully present a certificate that is (1) not yet valid or (2) no longer valid, related to lack of time checks in the _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls_x509, as used by (a) Exim, (b) OpenLDAP, and (c) libsoup.

Affected Software

Name Vendor Start Version End Version
Gnutls Gnu * 2.6.5 (including)
Gnutls Gnu 1.0.16 (including) 1.0.16 (including)
Gnutls Gnu 1.0.17 (including) 1.0.17 (including)
Gnutls Gnu 1.0.18 (including) 1.0.18 (including)
Gnutls Gnu 1.0.19 (including) 1.0.19 (including)
Gnutls Gnu 1.0.20 (including) 1.0.20 (including)
Gnutls Gnu 1.0.21 (including) 1.0.21 (including)
Gnutls Gnu 1.0.22 (including) 1.0.22 (including)
Gnutls Gnu 1.0.23 (including) 1.0.23 (including)
Gnutls Gnu 1.0.24 (including) 1.0.24 (including)
Gnutls Gnu 1.0.25 (including) 1.0.25 (including)
Gnutls Gnu 1.1.13 (including) 1.1.13 (including)
Gnutls Gnu 1.1.14 (including) 1.1.14 (including)
Gnutls Gnu 1.1.15 (including) 1.1.15 (including)
Gnutls Gnu 1.1.16 (including) 1.1.16 (including)
Gnutls Gnu 1.1.17 (including) 1.1.17 (including)
Gnutls Gnu 1.1.18 (including) 1.1.18 (including)
Gnutls Gnu 1.1.19 (including) 1.1.19 (including)
Gnutls Gnu 1.1.20 (including) 1.1.20 (including)
Gnutls Gnu 1.1.21 (including) 1.1.21 (including)
Gnutls Gnu 1.1.22 (including) 1.1.22 (including)
Gnutls Gnu 1.1.23 (including) 1.1.23 (including)
Gnutls Gnu 1.2.0 (including) 1.2.0 (including)
Gnutls Gnu 1.2.1 (including) 1.2.1 (including)
Gnutls Gnu 1.2.2 (including) 1.2.2 (including)
Gnutls Gnu 1.2.3 (including) 1.2.3 (including)
Gnutls Gnu 1.2.4 (including) 1.2.4 (including)
Gnutls Gnu 1.2.5 (including) 1.2.5 (including)
Gnutls Gnu 1.2.6 (including) 1.2.6 (including)
Gnutls Gnu 1.2.7 (including) 1.2.7 (including)
Gnutls Gnu 1.2.8 (including) 1.2.8 (including)
Gnutls Gnu 1.2.8.1a1 (including) 1.2.8.1a1 (including)
Gnutls Gnu 1.2.9 (including) 1.2.9 (including)
Gnutls Gnu 1.2.10 (including) 1.2.10 (including)
Gnutls Gnu 1.2.11 (including) 1.2.11 (including)
Gnutls Gnu 1.3.0 (including) 1.3.0 (including)
Gnutls Gnu 1.3.1 (including) 1.3.1 (including)
Gnutls Gnu 1.3.2 (including) 1.3.2 (including)
Gnutls Gnu 1.3.3 (including) 1.3.3 (including)
Gnutls Gnu 1.3.4 (including) 1.3.4 (including)
Gnutls Gnu 1.3.5 (including) 1.3.5 (including)
Gnutls Gnu 1.4.0 (including) 1.4.0 (including)
Gnutls Gnu 1.4.1 (including) 1.4.1 (including)
Gnutls Gnu 1.4.2 (including) 1.4.2 (including)
Gnutls Gnu 1.4.3 (including) 1.4.3 (including)
Gnutls Gnu 1.4.4 (including) 1.4.4 (including)
Gnutls Gnu 1.4.5 (including) 1.4.5 (including)
Gnutls Gnu 1.5.0 (including) 1.5.0 (including)
Gnutls Gnu 1.5.1 (including) 1.5.1 (including)
Gnutls Gnu 1.5.2 (including) 1.5.2 (including)
Gnutls Gnu 1.5.3 (including) 1.5.3 (including)
Gnutls Gnu 1.5.4 (including) 1.5.4 (including)
Gnutls Gnu 1.5.5 (including) 1.5.5 (including)
Gnutls Gnu 1.6.0 (including) 1.6.0 (including)
Gnutls Gnu 1.6.1 (including) 1.6.1 (including)
Gnutls Gnu 1.6.2 (including) 1.6.2 (including)
Gnutls Gnu 1.6.3 (including) 1.6.3 (including)
Gnutls Gnu 1.7.0 (including) 1.7.0 (including)
Gnutls Gnu 1.7.1 (including) 1.7.1 (including)
Gnutls Gnu 1.7.2 (including) 1.7.2 (including)
Gnutls Gnu 1.7.3 (including) 1.7.3 (including)
Gnutls Gnu 1.7.4 (including) 1.7.4 (including)
Gnutls Gnu 1.7.5 (including) 1.7.5 (including)
Gnutls Gnu 1.7.6 (including) 1.7.6 (including)
Gnutls Gnu 1.7.7 (including) 1.7.7 (including)
Gnutls Gnu 1.7.8 (including) 1.7.8 (including)
Gnutls Gnu 1.7.9 (including) 1.7.9 (including)
Gnutls Gnu 1.7.10 (including) 1.7.10 (including)
Gnutls Gnu 1.7.11 (including) 1.7.11 (including)
Gnutls Gnu 1.7.12 (including) 1.7.12 (including)
Gnutls Gnu 1.7.13 (including) 1.7.13 (including)
Gnutls Gnu 1.7.14 (including) 1.7.14 (including)
Gnutls Gnu 1.7.15 (including) 1.7.15 (including)
Gnutls Gnu 1.7.16 (including) 1.7.16 (including)
Gnutls Gnu 1.7.17 (including) 1.7.17 (including)
Gnutls Gnu 1.7.18 (including) 1.7.18 (including)
Gnutls Gnu 1.7.19 (including) 1.7.19 (including)
Gnutls Gnu 2.0.0 (including) 2.0.0 (including)
Gnutls Gnu 2.0.1 (including) 2.0.1 (including)
Gnutls Gnu 2.0.2 (including) 2.0.2 (including)
Gnutls Gnu 2.0.3 (including) 2.0.3 (including)
Gnutls Gnu 2.0.4 (including) 2.0.4 (including)
Gnutls Gnu 2.1.0 (including) 2.1.0 (including)
Gnutls Gnu 2.1.1 (including) 2.1.1 (including)
Gnutls Gnu 2.1.2 (including) 2.1.2 (including)
Gnutls Gnu 2.1.3 (including) 2.1.3 (including)
Gnutls Gnu 2.1.4 (including) 2.1.4 (including)
Gnutls Gnu 2.1.5 (including) 2.1.5 (including)
Gnutls Gnu 2.1.6 (including) 2.1.6 (including)
Gnutls Gnu 2.1.7 (including) 2.1.7 (including)
Gnutls Gnu 2.1.8 (including) 2.1.8 (including)
Gnutls Gnu 2.2.0 (including) 2.2.0 (including)
Gnutls Gnu 2.2.1 (including) 2.2.1 (including)
Gnutls Gnu 2.2.2 (including) 2.2.2 (including)
Gnutls Gnu 2.2.3 (including) 2.2.3 (including)
Gnutls Gnu 2.2.4 (including) 2.2.4 (including)
Gnutls Gnu 2.2.5 (including) 2.2.5 (including)
Gnutls Gnu 2.3.0 (including) 2.3.0 (including)
Gnutls Gnu 2.3.1 (including) 2.3.1 (including)
Gnutls Gnu 2.3.2 (including) 2.3.2 (including)
Gnutls Gnu 2.3.3 (including) 2.3.3 (including)
Gnutls Gnu 2.3.4 (including) 2.3.4 (including)
Gnutls Gnu 2.3.5 (including) 2.3.5 (including)
Gnutls Gnu 2.3.6 (including) 2.3.6 (including)
Gnutls Gnu 2.3.7 (including) 2.3.7 (including)
Gnutls Gnu 2.3.8 (including) 2.3.8 (including)
Gnutls Gnu 2.3.9 (including) 2.3.9 (including)
Gnutls Gnu 2.3.10 (including) 2.3.10 (including)
Gnutls Gnu 2.3.11 (including) 2.3.11 (including)
Gnutls Gnu 2.4.0 (including) 2.4.0 (including)
Gnutls Gnu 2.4.1 (including) 2.4.1 (including)
Gnutls Gnu 2.4.2 (including) 2.4.2 (including)
Gnutls Gnu 2.6.0 (including) 2.6.0 (including)
Gnutls Gnu 2.6.1 (including) 2.6.1 (including)
Gnutls Gnu 2.6.2 (including) 2.6.2 (including)
Gnutls Gnu 2.6.3 (including) 2.6.3 (including)
Gnutls Gnu 2.6.4 (including) 2.6.4 (including)
Gnutls11 Ubuntu dapper *
Gnutls12 Ubuntu dapper *
Gnutls13 Ubuntu hardy *
Gnutls26 Ubuntu intrepid *
Gnutls26 Ubuntu jaunty *
Gnutls26 Ubuntu upstream *

References