CVE Vulnerabilities

CVE-2009-1417

Published: Apr 30, 2009 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to successfully present a certificate that is (1) not yet valid or (2) no longer valid, related to lack of time checks in the _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls_x509, as used by (a) Exim, (b) OpenLDAP, and (c) libsoup.

Affected Software

Name Vendor Start Version End Version
Gnutls Gnu 2.3.5 2.3.5
Gnutls Gnu 1.6.0 1.6.0
Gnutls Gnu 2.0.0 2.0.0
Gnutls Gnu 1.5.0 1.5.0
Gnutls Gnu 1.2.8 1.2.8
Gnutls Gnu 1.1.14 1.1.14
Gnutls Gnu 2.3.4 2.3.4
Gnutls Gnu 1.7.3 1.7.3
Gnutls Gnu 1.4.1 1.4.1
Gnutls Gnu 1.4.3 1.4.3
Gnutls Gnu 2.6.1 2.6.1
Gnutls Gnu 1.2.11 1.2.11
Gnutls Gnu 1.1.21 1.1.21
Gnutls Gnu 1.7.5 1.7.5
Gnutls Gnu 1.7.11 1.7.11
Gnutls Gnu 1.0.20 1.0.20
Gnutls Gnu 1.2.5 1.2.5
Gnutls Gnu 2.2.4 2.2.4
Gnutls Gnu 1.0.17 1.0.17
Gnutls Gnu 1.2.4 1.2.4
Gnutls Gnu 1.3.1 1.3.1
Gnutls Gnu 1.0.24 1.0.24
Gnutls Gnu 1.7.15 1.7.15
Gnutls Gnu 1.6.1 1.6.1
Gnutls Gnu 1.0.21 1.0.21
Gnutls Gnu 1.4.2 1.4.2
Gnutls Gnu 1.7.8 1.7.8
Gnutls Gnu 1.7.0 1.7.0
Gnutls Gnu 2.1.0 2.1.0
Gnutls Gnu 2.3.1 2.3.1
Gnutls Gnu 1.0.16 1.0.16
Gnutls Gnu 2.2.5 2.2.5
Gnutls Gnu 2.1.1 2.1.1
Gnutls Gnu 2.3.8 2.3.8
Gnutls Gnu 1.7.18 1.7.18
Gnutls Gnu 1.1.20 1.1.20
Gnutls Gnu 2.1.7 2.1.7
Gnutls Gnu 2.1.4 2.1.4
Gnutls Gnu 1.2.10 1.2.10
Gnutls Gnu 1.5.3 1.5.3
Gnutls Gnu 1.1.22 1.1.22
Gnutls Gnu 1.6.3 1.6.3
Gnutls Gnu 2.6.0 2.6.0
Gnutls Gnu 2.1.6 2.1.6
Gnutls Gnu 1.4.5 1.4.5
Gnutls Gnu 1.5.1 1.5.1
Gnutls Gnu 1.4.0 1.4.0
Gnutls Gnu 1.7.4 1.7.4
Gnutls Gnu 1.7.13 1.7.13
Gnutls Gnu 2.3.2 2.3.2
Gnutls Gnu 2.3.9 2.3.9
Gnutls Gnu 2.2.2 2.2.2
Gnutls Gnu 2.2.0 2.2.0
Gnutls Gnu 2.3.11 2.3.11
Gnutls Gnu 1.3.4 1.3.4
Gnutls Gnu 2.6.2 2.6.2
Gnutls Gnu 1.0.19 1.0.19
Gnutls Gnu 1.7.2 1.7.2
Gnutls Gnu 1.2.1 1.2.1
Gnutls Gnu 1.1.19 1.1.19
Gnutls Gnu 2.0.4 2.0.4
Gnutls Gnu 2.6.3 2.6.3
Gnutls Gnu 1.1.18 1.1.18
Gnutls Gnu 1.5.4 1.5.4
Gnutls Gnu 1.7.9 1.7.9
Gnutls Gnu 2.4.0 2.4.0
Gnutls Gnu 2.1.3 2.1.3
Gnutls Gnu 2.4.1 2.4.1
Gnutls Gnu 1.7.10 1.7.10
Gnutls Gnu 1.1.13 1.1.13
Gnutls Gnu 1.2.8.1a1 1.2.8.1a1
Gnutls Gnu 2.3.7 2.3.7
Gnutls Gnu 2.0.3 2.0.3
Gnutls Gnu 1.2.2 1.2.2
Gnutls Gnu 1.7.19 1.7.19
Gnutls Gnu 1.5.5 1.5.5
Gnutls Gnu 1.2.0 1.2.0
Gnutls Gnu 1.0.18 1.0.18
Gnutls Gnu 1.2.7 1.2.7
Gnutls Gnu 1.3.2 1.3.2
Gnutls Gnu 1.0.25 1.0.25
Gnutls Gnu 1.1.15 1.1.15
Gnutls Gnu 2.1.2 2.1.2
Gnutls Gnu 1.0.23 1.0.23
Gnutls Gnu 2.4.2 2.4.2
Gnutls Gnu 1.3.0 1.3.0
Gnutls Gnu 1.3.5 1.3.5
Gnutls Gnu 1.7.14 1.7.14
Gnutls Gnu 1.1.23 1.1.23
Gnutls Gnu 1.2.3 1.2.3
Gnutls Gnu 2.6.4 2.6.4
Gnutls Gnu 1.2.6 1.2.6
Gnutls Gnu 2.3.6 2.3.6
Gnutls Gnu 1.2.9 1.2.9
Gnutls Gnu 1.7.17 1.7.17
Gnutls Gnu 2.3.3 2.3.3
Gnutls Gnu 2.1.8 2.1.8
Gnutls Gnu 1.7.7 1.7.7
Gnutls Gnu 2.0.1 2.0.1
Gnutls Gnu 1.7.6 1.7.6
Gnutls Gnu 2.2.1 2.2.1
Gnutls Gnu 2.1.5 2.1.5
Gnutls Gnu 1.7.1 1.7.1
Gnutls Gnu * 2.6.5
Gnutls Gnu 1.5.2 1.5.2
Gnutls Gnu 1.7.16 1.7.16
Gnutls Gnu 1.7.12 1.7.12
Gnutls Gnu 1.1.16 1.1.16
Gnutls Gnu 2.3.10 2.3.10
Gnutls Gnu 1.0.22 1.0.22
Gnutls Gnu 2.0.2 2.0.2
Gnutls Gnu 2.3.0 2.3.0
Gnutls Gnu 1.6.2 1.6.2
Gnutls Gnu 2.2.3 2.2.3
Gnutls Gnu 1.4.4 1.4.4
Gnutls Gnu 1.1.17 1.1.17
Gnutls Gnu 1.3.3 1.3.3

References