Description
The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1874-1 | New nss packages fix several vulnerabilities |
Debian DSA |
DSA-1888-1 | New openssl packages deprecate MD2 hash signatures |
Debian DSA |
DSA-1935-1 | New gnutls23/gnutls26 packages fix SSL certificate verification weakness |
EUVD |
EUVD-2009-2405 | The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large. |
Ubuntu USN |
USN-809-1 | GnuTLS vulnerabilities |
Ubuntu USN |
USN-810-1 | NSS vulnerabilities |
Ubuntu USN |
USN-830-1 | OpenSSL vulnerability |
Ubuntu USN |
USN-859-1 | OpenJDK vulnerabilities |
References
History
Thu, 27 Mar 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla network Security Services
|
|
| Weaknesses | CWE-310 | CWE-295 |
| CPEs | cpe:2.3:a:gnu:gnutls:1.0.17:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.0.18:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.0.19:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.0.20:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.0.21:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.0.22:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.0.23:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.0.24:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.0.25:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.1.13:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.1.14:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.1.15:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.1.16:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.1.17:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.1.18:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.1.19:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.1.20:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.1.21:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.1.22:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.1.23:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.10:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.11:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.2:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.3:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.4:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.5:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.6:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.7:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.8.1a1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.8:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.2.9:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.3.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.3.1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.3.2:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.3.3:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.3.4:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.3.5:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.4.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.4.1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.4.2:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.4.3:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.4.4:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.4.5:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.5.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.5.1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.5.2:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.5.3:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.5.4:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.5.5:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.6.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.6.1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.6.2:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.6.3:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.10:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.11:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.12:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.13:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.14:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.15:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.16:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.17:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.18:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.19:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.2:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.3:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.4:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.5:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.6:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.7:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.8:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:1.7.9:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.0.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.0.1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.0.2:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.0.3:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.0.4:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.1.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.1.1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.1.2:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.1.3:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.1.4:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.1.5:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.1.6:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.1.7:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.1.8:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.2.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.2.1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.2.2:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.2.3:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.2.4:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.2.5:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.3.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.3.10:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.3.11:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.3.1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.3.2:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.3.3:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.3.4:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.3.5:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.3.6:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.3.7:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.3.8:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.3.9:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.4.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.4.1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.4.2:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.5.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.6.0:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.6.1:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.6.2:*:*:*:*:*:*:* cpe:2.3:a:gnu:gnutls:2.7.4:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:*:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.10:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.11.2:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.11.4:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.11.7:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.11.8:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.12.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.12:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.2.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.2:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.3.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.3.2:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.3:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.4.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.4.2:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.4.3:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.4:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.5:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.6.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.6:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.7.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.7.2:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.7.3:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.7.5:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.7.7:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.7:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.8:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.9.5:*:*:*:*:*:*:* cpe:2.3:a:mozilla:nss:3.9:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:0.9.8j:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:0.9.8k:*:*:*:*:*:*:* |
cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:* cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* |
| Vendors & Products |
Mozilla firefox
Mozilla nss |
Mozilla network Security Services
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T05:52:14.899Z
Reserved: 2009-07-09T00:00:00.000Z
Link: CVE-2009-2409
No data.
Status : Deferred
Published: 2009-07-30T19:30:00.343
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-2409
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN