CVE-2009-2409

NameCVE-2009-2409
DescriptionThe Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1874-1, DSA-1888-1, DSA-1935-1
NVD severitymedium (attack range: remote)
Debian Bugs539895, 539899, 539901
Debian/oldoldstablenot vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gnutls26 (PTS)squeeze, squeeze (security)2.8.6-1+squeeze3fixed
squeeze (lts)2.8.6-1+squeeze5fixed
wheezy2.12.20-8+deb7u2fixed
wheezy (security)2.12.20-8+deb7u3fixed
nss (PTS)squeeze, squeeze (security)3.12.8-1+squeeze7fixed
squeeze (lts)3.12.8-1+squeeze11fixed
wheezy2:3.14.5-1+deb7u3fixed
wheezy (security)2:3.14.5-1+deb7u4fixed
jessie2:3.17.2-1.1fixed
stretch, sid2:3.19-1fixed
openjdk-6 (PTS)squeeze6b18-1.8.13-0+squeeze2fixed
squeeze (security)6b31-1.13.3-1~deb6u1fixed
squeeze (lts)6b35-1.13.7-1~deb6u1fixed
wheezy6b27-1.12.5-1fixed
wheezy (security)6b35-1.13.7-1~deb7u1fixed
sid6b35-1.13.7-1fixed
openssl (PTS)squeeze, squeeze (security)0.9.8o-4squeeze14fixed
squeeze (lts)0.9.8o-4squeeze20fixed
wheezy1.0.1e-2+deb7u13fixed
wheezy (security)1.0.1e-2+deb7u16fixed
jessie1.0.1k-3fixed
stretch, sid1.0.2a-1fixed
sun-java6 (PTS)squeeze/non-free6.26-0squeeze1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gnutls13source(unstable)(unfixed)medium
gnutls13sourceetch1.4.4-3+etch5mediumDSA-1935-1
gnutls26source(unstable)2.4.2-5low539901
gnutls26sourcelenny2.4.2-6+lenny2mediumDSA-1935-1
nsssource(unstable)3.12.3-1low539895
nsssourcelenny3.12.3.1-0lenny1mediumDSA-1874-1
openjdk-6source(unstable)6b17~pre3-1low
opensslsource(unstable)0.9.8k-4low539899
opensslsourceetch0.9.8c-4etch9mediumDSA-1888-1
opensslsourcelenny0.9.8g-15+lenny5mediumDSA-1888-1
openssl097sourceetch0.9.7k-3.1etch5mediumDSA-1888-1
sun-java6source(unstable)6-17-1medium
sun-java6sourcelenny6-20-0lenny1medium

Search for package or bug name: Reporting problems