CVE-2009-5138

Advisory lineage Upstream: 0 Downstream: 1
Downstream
Modified
Published: 06 Mar 2014, 18:00
Last modified:07 Aug 2024, 07:32

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
5.8 MEDIUM
v2.0 (nvd)
EPSS Score
0.85% LOW
1% probability -0.52%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

06 Mar 2014, 18:00
Published
Vulnerability first disclosed
07 Aug 2024, 07:32
Last Modified
Vulnerability information updated

Description

GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates, a different vulnerability than CVE-2014-1959.

CVSS Metrics

  • v2.0MEDIUMScore: 5.8AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 0.85% Percentile: 75%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • gnugnutls

    ≤ 2.7.5 | 2.7.0 | 2.7.1 | 2.7.2 | 2.7.3 | 2.7.4

References (14)