CVE-2009-1417
published 2009-04-30CVE-2009-1417: gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to successfully…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.43%
70.2th percentile
gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to successfully present a certificate that is (1) not yet valid or (2) no longer valid, related to lack of time checks in the _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls_x509, as used by (a) Exim, (b) OpenLDAP, and (c) libsoup.
Affected
117 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gnutls | <= 2.6.5 | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f5mp-3h5g-9fgh: gnutls-cli in GnuTLS before 2
ghsa_unreviewed·2022-05-02
CVE-2009-1417 [MEDIUM] GHSA-f5mp-3h5g-9fgh: gnutls-cli in GnuTLS before 2
gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to successfully present a certificate that is (1) not yet valid or (2) no longer valid, related to lack of time checks in the _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls_x509, as used by (a) Exim, (b) OpenLDAP, and (c) libsoup.
Red Hat
gnutls: certificate expiration not checked by gnutls-cli [GNUTLS-SA-2009-3]
vendor_redhat·2009-04-30·CVSS 5.0
CVE-2009-1417 [MEDIUM] gnutls: certificate expiration not checked by gnutls-cli [GNUTLS-SA-2009-3]
gnutls: certificate expiration not checked by gnutls-cli [GNUTLS-SA-2009-3]
gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to successfully present a certificate that is (1) not yet valid or (2) no longer valid, related to lack of time checks in the _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls_x509, as used by (a) Exim, (b) OpenLDAP, and (c) libsoup.
Statement: The Red Hat Product Security has rated this issue as having low security impact. The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 4, or 5.
For further details, see: https://bugzilla.redhat.
No detection rules found.
No public exploits indexed.
Bugzilla
Fix checking of certificate activation/expiration times in gnutls (GNUTLS-SA-2009-3 / CVE-2009-1417)
bugzilla·2009-06-09·CVSS 5.0
CVE-2009-1417 [MEDIUM] Fix checking of certificate activation/expiration times in gnutls (GNUTLS-SA-2009-3 / CVE-2009-1417)
Fix checking of certificate activation/expiration times in gnutls (GNUTLS-SA-2009-3 / CVE-2009-1417)
Created attachment 347024
Patched source RPM package
Description of problem:
GnuTLS applications (such as gnutls-cli) do not check the activation and expiration dates of X.509 certificates.
Version-Release number of selected component (if applicable):
2.4.2-3
How reproducible:
Use function _gnutls_x509_verify_certificate (in lib/x509/verify.c in libgnutls_x509). Such function is used by at least the following applications: (a) Exim, (b) OpenLDAP, and (c) libsoup
Steps to Reproduce:
1. Use function _gnutls_x509_verify_certificate on expired X.509 certificates
2. Or, use gnutls-cli on expired X.509 certificates
3. Example certificate for testing: expired.demo.gnutls.org
Actual results:
Bugzilla
CVE-2009-1417 gnutls: certificate expiration not checked by gnutls-cli [GNUTLS-SA-2009-3]
bugzilla·2009-04-28·CVSS 5.0
CVE-2009-1417 [MEDIUM] CVE-2009-1417 gnutls: certificate expiration not checked by gnutls-cli [GNUTLS-SA-2009-3]
CVE-2009-1417 gnutls: certificate expiration not checked by gnutls-cli [GNUTLS-SA-2009-3]
GnuTLS upstream reports:
Romain Francoise reported that gnutls-cli does not check the
activation and expiration dates of X.509 certificates. This is
assumed to apply to all versions of gnutls-cli.
Further upstream investigation of the problem showed that other applications using GnuTLS library may be affected by the similar problem, as GnuTLS' gnutls_certificate_verify_peers* functions do not check activation / expiration times on certificates. Such check was expected to be done by the applications using GnuTLS library.
This decision was now re-considered upstream and activation / expiration time checks are being added to _gnutls_x509_verify_certificate in the GnuTLS library, instead of only being
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3517http://secunia.com/advisories/34842http://secunia.com/advisories/35211http://security.gentoo.org/glsa/glsa-200905-04.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:116http://www.securityfocus.com/bid/34783http://www.securitytracker.com/id?1022159http://www.vupen.com/english/advisories/2009/1218https://exchange.xforce.ibmcloud.com/vulnerabilities/50261http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3517http://secunia.com/advisories/34842http://secunia.com/advisories/35211http://security.gentoo.org/glsa/glsa-200905-04.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:116http://www.securityfocus.com/bid/34783http://www.securitytracker.com/id?1022159http://www.vupen.com/english/advisories/2009/1218https://exchange.xforce.ibmcloud.com/vulnerabilities/50261
2009-04-30
Published