HIGH
gnutls: All DSA keys generated using GnuTLS 2.6.x are corrupt [GNUTLS-SA-2009-2]
Published Apr 30, 2009
7.5
HIGHCVSS 2.0
EPSS 3.90%
Description
lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by leveraging an invalid DSA key.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect versions of gnutls shipped in Red Hat Enterprise Linux 4 and 5 as it only affected gnutls 2.6.x versions.
Weaknesses (1)
References (14)
- http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3516 mailing-listx_refsource_MLISTExploitPatch
- http://lists.gnu.org/archive/html/help-gnutls/2009-04/msg00018.html mailing-listx_refsource_MLISTVendor Advisory
- http://secunia.com/advisories/34842 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35211 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200905-04.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:116 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/bid/34783 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1022158 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2009/1218 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-1416 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=498424 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1414 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-1416
- https://www.cve.org/CVERecord?id=CVE-2009-1416
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 30, 2009
Updated Aug 7, 2024
Reserved Apr 24, 2009
Link CVE-2009-1416
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-1414 Assigner mitre
Published Apr 30, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-1414