Unrated severityNVD Advisory· Published Jul 30, 2009· Updated Apr 23, 2026
CVE-2009-2409
CVE-2009-2409
Description
The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.
Affected products
3- cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:*Range: <3.12.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
37- java.sun.com/j2se/1.5.0/ReleaseNotes.htmlnvdPatch
- lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlnvdVendor Advisory
- secunia.com/advisories/36139nvdVendor Advisory
- secunia.com/advisories/36157nvdVendor Advisory
- secunia.com/advisories/36434nvdVendor Advisory
- security.gentoo.org/glsa/glsa-200911-02.xmlnvdThird Party Advisory
- security.gentoo.org/glsa/glsa-200912-01.xmlnvdThird Party Advisory
- www.redhat.com/support/errata/RHSA-2009-1207.htmlnvdThird Party Advisory
- www.redhat.com/support/errata/RHSA-2009-1432.htmlnvdThird Party Advisory
- www.ubuntu.com/usn/usn-810-1nvdThird Party Advisory
- www.vmware.com/security/advisories/VMSA-2010-0019.htmlnvdThird Party Advisory
- www.vupen.com/english/advisories/2009/2085nvdVendor Advisory
- www.vupen.com/english/advisories/2009/3184nvdVendor Advisory
- www.vupen.com/english/advisories/2010/3126nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdThird Party Advisory
- lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.htmlnvdThird Party Advisory
- lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2010-0095.htmlnvdThird Party Advisory
- www.debian.org/security/2009/dsa-1888nvdMailing ListThird Party Advisory
- java.sun.com/javase/6/webnotes/6u17.htmlnvdRelease Notes
- secunia.com/advisories/36669nvdNot Applicable
- secunia.com/advisories/36739nvdNot Applicable
- secunia.com/advisories/37386nvdNot Applicable
- secunia.com/advisories/42467nvdNot Applicable
- support.apple.com/kb/HT3937nvdBroken Link
- www.debian.org/security/2009/dsa-1874nvdMailing List
- www.mandriva.com/security/advisoriesnvdNot Applicable
- www.mandriva.com/security/advisoriesnvdNot Applicable
- www.mandriva.com/security/advisoriesnvdNot Applicable
- www.mandriva.com/security/advisoriesnvdNot Applicable
- www.securityfocus.com/archive/1/515055/100/0/threadednvdBroken Link
- www.securitytracker.com/idnvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10763nvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6631nvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7155nvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8594nvdBroken Link
- usn.ubuntu.com/810-2/nvdBroken Link
News mentions
0No linked articles in our index yet.