CVE-2009-2409

NameCVE-2009-2409
DescriptionThe Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1874-1, DSA-1888-1, DSA-1935-1
NVD severitymedium
Debian Bugs539895, 539899, 539901

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nss (PTS)jessie2:3.26-1+debu8u3fixed
jessie (security)2:3.26-1+debu8u6fixed
stretch (security), stretch2:3.26.2-1.1+deb9u1fixed
buster2:3.42.1-1+deb10u1fixed
bullseye, sid2:3.45-1fixed
openssl (PTS)jessie1.0.1t-1+deb8u8fixed
jessie (security)1.0.1t-1+deb8u12fixed
stretch1.1.0k-1~deb9u1fixed
stretch (security)1.1.0l-1~deb9u1fixed
buster1.1.1c-1fixed
buster (security)1.1.1d-0+deb10u2fixed
bullseye, sid1.1.1d-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gnutls13source(unstable)(unfixed)
gnutls13sourceetch1.4.4-3+etch5DSA-1935-1
gnutls26source(unstable)2.4.2-5low539901
gnutls26sourcelenny2.4.2-6+lenny2DSA-1935-1
nsssource(unstable)3.12.3-1low539895
nsssourcelenny3.12.3.1-0lenny1DSA-1874-1
openjdk-6source(unstable)6b17~pre3-1low
opensslsource(unstable)0.9.8k-4low539899
opensslsourceetch0.9.8c-4etch9DSA-1888-1
opensslsourcelenny0.9.8g-15+lenny5DSA-1888-1
openssl097sourceetch0.9.7k-3.1etch5DSA-1888-1
sun-java6source(unstable)6-17-1
sun-java6sourcelenny6-20-0lenny1

Search for package or bug name: Reporting problems