CVE-2009-2409

The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time.  NOTE: the scope of this issue is currently limited because the amount of computation required is still large.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
gnugnutls
𝑥
< 2.6.4
gnugnutls
2.7.0 ≤
𝑥
< 2.7.4
mozillanetwork_security_services
𝑥
< 3.12.3
opensslopenssl
0.9.8 ≤
𝑥
≤ 0.9.8k
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nss
bullseye
2:3.61-1+deb11u3
fixed
bullseye (security)
2:3.61-1+deb11u4
fixed
bookworm
2:3.87.1-1
fixed
sid
2:3.105-2
fixed
trixie
2:3.105-2
fixed
openssl
bullseye
1.1.1w-0+deb11u1
fixed
bullseye (security)
1.1.1w-0+deb11u2
fixed
bookworm
3.0.14-1~deb12u1
fixed
bookworm (security)
3.0.14-1~deb12u2
fixed
sid
3.3.2-2
fixed
trixie
3.3.2-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnutls12
maverick
dne
lucid
dne
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
Fixed 1.2.9-2ubuntu1.5
released
gnutls13
maverick
dne
lucid
dne
karmic
dne
jaunty
dne
intrepid
dne
hardy
Fixed 2.0.4-1ubuntu2.5
released
dapper
dne
gnutls26
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
Fixed 2.4.2-5
released
intrepid
Fixed 2.4.1-1ubuntu0.3
released
hardy
dne
dapper
dne
nss
maverick
not-affected
lucid
not-affected
karmic
Fixed 3.12.3.1-0ubuntu1
released
jaunty
Fixed 3.12.3.1-0ubuntu0.9.04.1
released
intrepid
Fixed 3.12.3.1-0ubuntu0.8.10.1
released
hardy
Fixed 3.12.3.1-0ubuntu0.8.04.1
released
dapper
dne
openjdk-6
maverick
not-affected
lucid
not-affected
karmic
Fixed 6b16-1.6.1-3ubuntu1
released
jaunty
Fixed 6b14-1.4.1-0ubuntu12
released
intrepid
Fixed 6b12-0ubuntu6.6
released
hardy
Fixed 6b18-1.8.2-4ubuntu1~8.04.1
released
dapper
dne
openssl
maverick
not-affected
lucid
not-affected
karmic
Fixed 0.9.8g-16ubuntu3
released
jaunty
Fixed 0.9.8g-15ubuntu3.3
released
intrepid
Fixed 0.9.8g-10.1ubuntu2.5
released
hardy
Fixed 0.9.8g-4ubuntu3.8
released
dapper
Fixed 0.9.8a-7ubuntu0.10
released
References