CVE-2009-1417 describes a vulnerability in GnuTLS before version 2.6.6, specifically in the gnutls-cli component, where it fails to validate the activation and expiration times of X.509 certificates. This flaw allows remote attackers to present invalid certificates (either not yet valid or expired) to applications like Exim, OpenLDAP, and libsoup that rely on GnuTLS. The vulnerability has a CVSS score of 5.0, indicating a medium severity with low attack complexity, requiring no authentication, and potentially leading to information integrity compromise (I:P). While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, the CVE has received some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.5CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* | ||
1.0.16CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.16:*:*:*:*:*:*:* | ||
1.0.17CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.17:*:*:*:*:*:*:* | ||
1.0.18CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.18:*:*:*:*:*:*:* | ||
1.0.19CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.19:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.