Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-2409

21
FAUCET Score

CVE-2009-2409 describes a vulnerability in the Network Security Services (NSS) library, GnuTLS, and OpenSSL versions 0.9.8 through 0.9.8k, allowing remote attackers to potentially spoof X.509 certificates. This is due to design flaws in the MD2 hashing algorithm, which could enable hash collisions in less than brute-force time. The vulnerability has a CVSS score of 5.1 (medium severity) with a network attack vector and high attack complexity, potentially leading to partial confidentiality, integrity, and availability impacts. While the amount of computation required for exploitation was considered large at the time, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.6.4CPE matchmatch criteria
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*
>= 2.7.0, < 2.7.4CPE matchmatch criteria
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*
< 3.12.3CPE matchmatch criteria
cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:*
>= 0.9.8, <= 0.9.8kCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.1MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.51%
Probability of exploitation in next 30 days
EPSS Percentile
90.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0451 is in the 88th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (19)

redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.6.0-sun-1:1.6.0.17-1jpp.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.5.0-sun-0:1.5.0.22-1jpp.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: seamonkey-0:1.0.9-0.45.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: openssl-0:0.9.7a-33.26
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: nspr-0:4.7.4-1.el4_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: nss-0:3.12.3.99.3-1.el4_8.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: openssl-0:0.9.7a-43.17.el4_8.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4.7 Z StreamFixed in: nspr-0:4.7.4-1.el4_7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4.7 Z StreamFixed in: nss-0:3.12.3.99.3-1.el4_7.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: nspr-0:4.7.4-1.el5_3.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: nss-0:3.12.3.99.3-1.el5_3.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: java-1.6.0-openjdk-1:1.6.0.0-1.7.b09.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openssl-0:0.9.8e-12.el5_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: gnutls-0:1.4.1-3.el5_4.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.2 Z StreamFixed in: nspr-0:4.7.4-1.el5_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.2 Z StreamFixed in: nss-0:3.12.3.99.3-1.el5_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.1Fixed in: java-1.5.0-sun-0:1.5.0.22-1jpp.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.6.0-sun-1:1.6.0.17-1jpp.2.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.5.0-sun-0:1.5.0.22-1jpp.1.el5
View patch

Vendor Advisories (1)

redhatCVE-2009-2409Moderate

deprecate MD2 in SSL cert validation (Kaminsky)

Jul 29, 2009

References

java.sun.com / j2se/1.5.0/ReleaseNotes.html
Patch
java.sun.com / javase/6/webnotes/6u17.html
Release Notes
lists.apple.com / archives/security-announce/2009/Nov/msg00000.html
Vendor Advisory
bugzilla.redhat.com / show_bug.cgi
Third Party Advisory
secunia.com / advisories/36139
Vendor Advisory
secunia.com / advisories/36157
Vendor Advisory
secunia.com / advisories/36434
Vendor Advisory
secunia.com / advisories/36669
Not Applicable
secunia.com / advisories/36739
Not Applicable
secunia.com / advisories/37386
Not Applicable
secunia.com / advisories/42467
Not Applicable
security.gentoo.org / glsa/glsa-200911-02.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-200912-01.xml
Third Party Advisory
lists.balabit.com / pipermail/syslog-ng-announce/2011-January/000101.html
Third Party Advisory
lists.balabit.com / pipermail/syslog-ng-announce/2011-January/000102.html
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10763
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6631
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7155
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8594
Broken Link
rhn.redhat.com / errata/RHSA-2010-0095.html
Third Party Advisory
support.apple.com / kb/HT3937
Broken Link
usn.ubuntu.com / 810-2
Broken Link
debian.org / security/2009/dsa-1888
Mailing ListThird Party Advisory
debian.org / security/2009/dsa-1874
Mailing List
mandriva.com / security/advisories
Not Applicable
mandriva.com / security/advisories
Not Applicable
mandriva.com / security/advisories
Not Applicable
mandriva.com / security/advisories
Not Applicable
redhat.com / support/errata/RHSA-2009-1207.html
Third Party Advisory
redhat.com / support/errata/RHSA-2009-1432.html
Third Party Advisory
securityfocus.com / archive/1/515055/100/0/threaded
Broken Link
securitytracker.com / id
Broken Link
ubuntu.com / usn/usn-810-1
Third Party Advisory
vmware.com / security/advisories/VMSA-2010-0019.html
Third Party Advisory
vupen.com / english/advisories/2009/2085
Vendor Advisory
vupen.com / english/advisories/2009/3184
Vendor Advisory
vupen.com / english/advisories/2010/3126
Vendor Advisory