Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2009-5138

Overview

Vulnerability Score 5.8 5.8
CVE Id CVE-2009-5138
Last Modified 01 Apr 2014 01:44:14
Published 06 Mar 2014 07:10:53
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2009-5138

Summary

GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates, a different vulnerability than CVE-2014-1959.

Vulnerable Systems

Application

  • Gnutls 2.7.0

  • Gnutls 2.7.1

  • Gnutls 2.7.2

  • Gnutls 2.7.3

  • Gnutls 2.7.4

  • Gnutls 2.7.5


References

CONFIRM - https://gitorious.org/gnutls/gnutls/commit/c8dcbedd1fdc312f5b1a70fcfbc1afe235d800cd

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=1069301

MLIST - [oss-security] 20140227 Re: CVE Request - GnuTLS corrects flaw in certificate verification (3.1.x/3.2.x)

MLIST - [gnutls-devel] 20090109 Re: gnutls fails to use Verisign CA cert without a Basic Constraint

REDHAT - RHSA-2014:0247

SUSE - SUSE-SU-2014:0319

MLIST - [oss-security] 20140225 Re: Re: CVE Request - GnuTLS corrects flaw in certificate verification (3.1.x/3.2.x)

SUSE - SUSE-SU-2014:0322

SUSE - SUSE-SU-2014:0320

SECUNIA - 57321

SECUNIA - 57274

SECUNIA - 57260

SECUNIA - 57254

SUSE - SUSE-SU-2014:0445


Last Updated: 27 May 2016 11:04:46