CVE-2009-2409

NameCVE-2009-2409
DescriptionThe Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1874-1, DSA-1888-1, DSA-1935-1
NVD severitymedium (attack range: remote)
Debian Bugs539895, 539899, 539901

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gnutls26 (PTS)wheezy (security), wheezy2.12.20-8+deb7u5fixed
nss (PTS)wheezy2:3.14.5-1+deb7u5fixed
wheezy (security)2:3.14.5-1+deb7u8fixed
jessie2:3.17.2-1.1+deb8u2fixed
jessie (security)2:3.17.2-1.1+deb8u1fixed
stretch2:3.25-1fixed
sid2:3.26-2fixed
openjdk-6 (PTS)wheezy (security), wheezy6b38-1.13.10-1~deb7u1fixed
openssl (PTS)wheezy1.0.1e-2+deb7u20fixed
wheezy (security)1.0.1t-1+deb7u1fixed
jessie1.0.1t-1+deb8u3fixed
jessie (security)1.0.1t-1+deb8u5fixed
stretch1.0.2h-1fixed
sid1.0.2i-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gnutls13source(unstable)(unfixed)medium
gnutls13sourceetch1.4.4-3+etch5mediumDSA-1935-1
gnutls26source(unstable)2.4.2-5low539901
gnutls26sourcelenny2.4.2-6+lenny2mediumDSA-1935-1
nsssource(unstable)3.12.3-1low539895
nsssourcelenny3.12.3.1-0lenny1mediumDSA-1874-1
openjdk-6source(unstable)6b17~pre3-1low
opensslsource(unstable)0.9.8k-4low539899
opensslsourceetch0.9.8c-4etch9mediumDSA-1888-1
opensslsourcelenny0.9.8g-15+lenny5mediumDSA-1888-1
openssl097sourceetch0.9.7k-3.1etch5mediumDSA-1888-1
sun-java6source(unstable)6-17-1medium
sun-java6sourcelenny6-20-0lenny1medium

Search for package or bug name: Reporting problems