Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2409

Опубликовано: 30 июл. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.1

Описание

The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.

РелизСтатусПримечание
dapper

released

1.2.9-2ubuntu1.5
devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

lucid

DNE

maverick

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

released

2.0.4-1ubuntu2.5
intrepid

DNE

jaunty

DNE

karmic

DNE

lucid

DNE

maverick

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

intrepid

released

2.4.1-1ubuntu0.3
jaunty

released

2.4.2-5
karmic

not-affected

2.6.6-1
lucid

not-affected

maverick

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

released

3.12.3.1-0ubuntu0.8.04.1
intrepid

released

3.12.3.1-0ubuntu0.8.10.1
jaunty

released

3.12.3.1-0ubuntu0.9.04.1
karmic

released

3.12.3.1-0ubuntu1
lucid

not-affected

maverick

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6b17~pre2-0ubuntu3
hardy

released

6b18-1.8.2-4ubuntu1~8.04.1
intrepid

released

6b12-0ubuntu6.6
jaunty

released

6b14-1.4.1-0ubuntu12
karmic

released

6b16-1.6.1-3ubuntu1
lucid

not-affected

6b17~pre2-0ubuntu3
maverick

not-affected

6b17~pre2-0ubuntu3
upstream

released

6b17

Показывать по

РелизСтатусПримечание
dapper

released

0.9.8a-7ubuntu0.10
devel

not-affected

hardy

released

0.9.8g-4ubuntu3.8
intrepid

released

0.9.8g-10.1ubuntu2.5
jaunty

released

0.9.8g-15ubuntu3.3
karmic

released

0.9.8g-16ubuntu3
lucid

not-affected

maverick

not-affected

upstream

needs-triage

Показывать по

EPSS

Процентиль: 83%
0.02015
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

redhat
почти 16 лет назад

The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.

nvd
почти 16 лет назад

The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.

debian
почти 16 лет назад

The Network Security Services (NSS) library before 3.12.3, as used in ...

github
около 3 лет назад

The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.

oracle-oval
около 15 лет назад

ELSA-2010-0166: gnutls security update (MODERATE)

EPSS

Процентиль: 83%
0.02015
Низкий

5.1 Medium

CVSS2