CVE-2009-1416 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 3.9% (pctl 90)
Patch early
A public exploit exists.
Description
lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by leveraging an invalid DSA key.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 3.9% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-310 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-04-30 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| gnu | gnutls |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GnuTLS 2.6.x - libgnutls lib/gnutls_pk.c DSA Key Storage Remote Spoofing | 2009-04-30 |
References
- http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3516
- http://lists.gnu.org/archive/html/help-gnutls/2009-04/msg00018.html
- http://secunia.com/advisories/34842
- http://secunia.com/advisories/35211
- http://security.gentoo.org/glsa/glsa-200905-04.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:116
- http://www.securityfocus.com/bid/34783
- http://www.securitytracker.com/id?1022158
- http://www.vupen.com/english/advisories/2009/1218
- http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3516
- http://lists.gnu.org/archive/html/help-gnutls/2009-04/msg00018.html
- http://secunia.com/advisories/34842
- http://secunia.com/advisories/35211
- http://security.gentoo.org/glsa/glsa-200905-04.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:116
- http://www.securityfocus.com/bid/34783
- http://www.securitytracker.com/id?1022158
- http://www.vupen.com/english/advisories/2009/1218
→ the Explorer · watch your stack · NVD