CVE-2009-2409

Advisory lineage Upstream: 0 Downstream: 16
Modified
Published: 30 Jul 2009, 19:00
Last modified:07 Aug 2024, 05:52

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.1 MEDIUM
v2.0 (nvd)
EPSS Score
2.21% LOW
2% probability -0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jul 2009, 19:00
Published
Vulnerability first disclosed
07 Aug 2024, 05:52
Last Modified
Vulnerability information updated

Description

The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.

CVSS Metrics

  • v2.0MEDIUMScore: 5.1AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 2.21% Percentile: 85%

Techniques & Countermeasures

  • CWE-295Improper Certificate Validation

    The product does not validate, or incorrectly validates, a certificate.

Affected Systems

  • gnugnutls

    < 2.6.4 | ≥ 2.7.0, < 2.7.4

  • mozillanetwork_security_services

    < 3.12.3

  • UnknownOpenSSL

    ≥ 0.9.8, ≤ 0.9.8k

References (37)