CVE-2009-1416
CVE-2009-1416
lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by leveraging an invalid DSA key.
Productos afectados
n/a · n/aPoCs públicas encontradas — 1
exploitdbwww.exploit-db.com/exploits/32965no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3516http://lists.gnu.org/archive/html/help-gnutls/2009-04/msg00018.htmlhttp://secunia.com/advisories/34842http://secunia.com/advisories/35211http://security.gentoo.org/glsa/glsa-200905-04.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:116http://www.securityfocus.com/bid/34783http://www.securitytracker.com/id?1022158http://www.vupen.com/english/advisories/2009/1218