CVE-2009-2409

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
30/07/2009
Last modified:
09/04/2025

Description

The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* 2.6.4 (excluding)
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* 2.7.0 (including) 2.7.4 (excluding)
cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:* 3.12.3 (excluding)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 0.9.8 (including) 0.9.8k (including)


References to Advisories, Solutions, and Tools