CVE Vulnerabilities

CVE-2009-2409

Improper Certificate Validation

Published: Jul 30, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
2.6 MODERATE
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
GnutlsGnu*2.6.4 (excluding)
GnutlsGnu2.7.0 (including)2.7.4 (excluding)
Network_security_servicesMozilla*3.12.3 (excluding)
OpensslOpenssl0.9.8 (including)0.9.8k (including)
Extras for RHEL 4RedHatjava-1.6.0-sun-1:1.6.0.17-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.1.el4*
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.45.el3*
Red Hat Enterprise Linux 3RedHatopenssl-0:0.9.7a-33.26*
Red Hat Enterprise Linux 4RedHatnspr-0:4.7.4-1.el4_8.1*
Red Hat Enterprise Linux 4RedHatnss-0:3.12.3.99.3-1.el4_8.2*
Red Hat Enterprise Linux 4RedHatopenssl-0:0.9.7a-43.17.el4_8.5*
Red Hat Enterprise Linux 4.7 Z StreamRedHatnspr-0:4.7.4-1.el4_7.1*
Red Hat Enterprise Linux 4.7 Z StreamRedHatnss-0:3.12.3.99.3-1.el4_7.6*
Red Hat Enterprise Linux 5RedHatnspr-0:4.7.4-1.el5_3.1*
Red Hat Enterprise Linux 5RedHatnss-0:3.12.3.99.3-1.el5_3.2*
Red Hat Enterprise Linux 5RedHatjava-1.6.0-openjdk-1:1.6.0.0-1.7.b09.el5*
Red Hat Enterprise Linux 5RedHatopenssl-0:0.9.8e-12.el5_4.1*
Red Hat Enterprise Linux 5RedHatgnutls-0:1.4.1-3.el5_4.8*
Red Hat Enterprise Linux 5.2 Z StreamRedHatnspr-0:4.7.4-1.el5_2*
Red Hat Enterprise Linux 5.2 Z StreamRedHatnss-0:3.12.3.99.3-1.el5_2*
Red Hat Network Satellite Server v 5.1RedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.1.el4*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-sun-1:1.6.0.17-1jpp.2.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.1.el5*
Gnutls12Ubuntudapper*
Gnutls13Ubuntuhardy*
Gnutls26Ubuntuintrepid*
Gnutls26Ubuntujaunty*
NssUbuntuhardy*
NssUbuntuintrepid*
NssUbuntujaunty*
NssUbuntukarmic*
Openjdk-6Ubuntuhardy*
Openjdk-6Ubuntuintrepid*
Openjdk-6Ubuntujaunty*
Openjdk-6Ubuntukarmic*
Openjdk-6Ubuntuupstream*
OpensslUbuntudapper*
OpensslUbuntuhardy*
OpensslUbuntuintrepid*
OpensslUbuntujaunty*
OpensslUbuntukarmic*

Potential Mitigations

References