[gnutls-devel] 20090430 All DSA keys generated using GnuTLS 2.6.x are corrupt [GNUTLS-SA-2009-2] [CVE-2009-1416]mailing list
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3516 CVE-2009-1416
GnuTLS 2.6.x - libgnutls lib/gnutls_pk.c DSA Key Storage Remote Spoofing
Record summary
CVE-2009-1416 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by leveraging an invalid DSA key.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGnuTLS 2.6.x - libgnutls lib/gnutls_pk.c DSA Key Storage Remote SpoofingExploitDB exploitby Miroslav KratochvilNot analyzed1 file
References
10[help-gnutls] 20090420 Encryption using DSA keysmailing list
http://lists.gnu.org/archive/html/help-gnutls/2009-04/msg00018.html 34842Third-party advisory
http://secunia.com/advisories/34842 35211Third-party advisory
http://secunia.com/advisories/35211 GLSA-200905-04Vendor advisory
http://security.gentoo.org/glsa/glsa-200905-04.xml MDVSA-2009:116Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2009:116 34783vdb entry
http://www.securityfocus.com/bid/34783 1022158vdb entry
http://www.securitytracker.com/id?1022158 ADV-2009-1218vdb entry
http://www.vupen.com/english/advisories/2009/1218 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-1416