CVE-2009-1416

EUVD-2009-1414
lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by leveraging an invalid DSA key.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Affected Products (NVD)
VendorProductVersion
gnugnutls
2.5.0
gnugnutls
2.6.0
gnugnutls
2.6.1
gnugnutls
2.6.2
gnugnutls
2.6.3
gnugnutls
2.6.4
gnugnutls
2.6.5
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnutls11
dapper
not-affected
hardy
dne
intrepid
dne
jaunty
dne
gnutls12
dapper
not-affected
hardy
dne
intrepid
dne
jaunty
dne
gnutls13
dapper
dne
hardy
not-affected
intrepid
dne
jaunty
dne
gnutls26
dapper
dne
hardy
dne
intrepid
not-affected
jaunty
not-affected
Common Weakness Enumeration