VDB
CVE-2009-1415
CVE-2009-1415
PUBLISHED
CVSS 4.300000190734863 MEDIUM
lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a malformed DSA key that triggers a (1) free of an uninitialized pointer or (2) double free.
EPSS 17.76% · 95.3th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
17.76%
95.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gnu | gnutls | 0 |
| n/a | n/a | n/a |
Timeline
- Apr 30, 2009 PoC Published
- Apr 30, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 19, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- gnutls-libgnutls-dos(50445) vdb
- [gnutls-devel] 20090423 Re: some crashes on using DSA keys mailing-list
- [gnutls-devel] 20090430 Double free and free of invalid pointer on certain errors [GNUTLS-SA-2009-1] [CVE-2009-1415] mailing-list
- gnutls-dsa-code-execution(50257) vdb
- http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3488 url
- gnutls-dsa-dos(50260) vdb
- ADV-2009-1218 vdb
- 34783 vdb
- GLSA-200905-04 vendor-advisory
- 1022157 vdb
- 34842 third-party-advisory
- 35211 third-party-advisory
- MDVSA-2009:116 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-1415 advisory