peter bassill · operator
$ cve CVE-2009-1416 JSON

CVE-2009-1416 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.9% (pctl 90)

Patch early

A public exploit exists.

Description

lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by leveraging an invalid DSA key.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.9% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-310
On CISA KEVno
Public exploityes
Published2009-04-30
Last modified2026-06-16

Affected (1)

VendorProduct
gnugnutls

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD