CVE Database
/

CVE-2008-1948

Back to search

CVE-2008-1948

Published: May 21, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate the number of Server Names in a TLS 1.0 Client Hello message during extension handling, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a zero value for the length of Server Names, which leads to a buffer overflow in session resumption data in the pack_security_parameters function, aka GNUTLS-SA-2008-1-1.

VendorProductVersions

n/a

n/a

affected
n/a

References

30331
third-party-advisory
x_refsource_SECUNIA
31939
third-party-advisory
x_refsource_SECUNIA
USN-613-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SA:2008:046
vendor-advisory
x_refsource_SUSE
RHSA-2008:0492
vendor-advisory
x_refsource_REDHAT
GLSA-200805-20
vendor-advisory
x_refsource_GENTOO
30355
third-party-advisory
x_refsource_SECUNIA
30317
third-party-advisory
x_refsource_SECUNIA
20080520 Vulnerability Advisory on GnuTLS
mailing-list
x_refsource_BUGTRAQ
RHSA-2008:0489
vendor-advisory
x_refsource_REDHAT
20080522 rPSA-2008-0174-1 gnutls
mailing-list
x_refsource_BUGTRAQ
VU#111034
third-party-advisory
x_refsource_CERT-VN
30324
third-party-advisory
x_refsource_SECUNIA
30302
third-party-advisory
x_refsource_SECUNIA
ADV-2008-1583
vdb-entry
x_refsource_VUPEN
29292
vdb-entry
x_refsource_BID
FEDORA-2008-4274
vendor-advisory
x_refsource_FEDORA
30330
third-party-advisory
x_refsource_SECUNIA
ADV-2008-1582
vdb-entry
x_refsource_VUPEN
30338
third-party-advisory
x_refsource_SECUNIA
DSA-1581
vendor-advisory
x_refsource_DEBIAN
FEDORA-2008-4259
vendor-advisory
x_refsource_FEDORA
3902
third-party-advisory
x_refsource_SREASON
1020057
vdb-entry
x_refsource_SECTRACK
30287
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:10935
vdb-entry
signature
x_refsource_OVAL
FEDORA-2008-4183
vendor-advisory
x_refsource_FEDORA
MDVSA-2008:106
vendor-advisory
x_refsource_MANDRIVA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now