CVE-2009-2409

NameCVE-2009-2409
DescriptionThe Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1874-1, DSA-1888-1, DSA-1935-1
Debian Bugs539895, 539899, 539901

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nss (PTS)bullseye2:3.61-1+deb11u3fixed
bullseye (security)2:3.61-1+deb11u4fixed
bookworm2:3.87.1-1fixed
sid, trixie2:3.105-2fixed
openssl (PTS)bullseye1.1.1w-0+deb11u1fixed
bullseye (security)1.1.1n-0+deb11u6fixed
bookworm3.0.14-1~deb12u1fixed
bookworm (security)3.0.14-1~deb12u2fixed
sid, trixie3.3.2-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gnutls13sourceetch1.4.4-3+etch5DSA-1935-1
gnutls13source(unstable)(unfixed)
gnutls26sourcelenny2.4.2-6+lenny2DSA-1935-1
gnutls26source(unstable)2.4.2-5low539901
nsssourcelenny3.12.3.1-0lenny1DSA-1874-1
nsssource(unstable)3.12.3-1low539895
openjdk-6source(unstable)6b17~pre3-1low
opensslsourceetch0.9.8c-4etch9DSA-1888-1
opensslsourcelenny0.9.8g-15+lenny5DSA-1888-1
opensslsource(unstable)0.9.8k-4low539899
openssl097sourceetch0.9.7k-3.1etch5DSA-1888-1
sun-java6sourcelenny6-20-0lenny1
sun-java6source(unstable)6-17-1

Search for package or bug name: Reporting problems