Back

HIGH

gnutls: All DSA keys generated using GnuTLS 2.6.x are corrupt [GNUTLS-SA-2009-2]

Published Apr 30, 2009

Description

lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by leveraging an invalid DSA key.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect versions of gnutls shipped in Red Hat Enterprise Linux 4 and 5 as it only affected gnutls 2.6.x versions.

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 30, 2009
Updated Aug 7, 2024
Reserved Apr 24, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Apr 30, 2009
ENISA EUVD
Assigner mitre
Published Apr 30, 2009
Updated Aug 7, 2024
Exploited since n/a
EUVD-2009-1414