CVE-2008-1949

The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, which allows remote attackers to cause a denial of service (NULL dereference and crash) via a TLS message containing multiple Client Hello messages, aka GNUTLS-SA-2008-1-2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
gnugnutls
1.0.18
gnugnutls
1.0.19
gnugnutls
1.0.20
gnugnutls
1.0.21
gnugnutls
1.0.22
gnugnutls
1.0.23
gnugnutls
1.0.24
gnugnutls
1.0.25
gnugnutls
1.1.13
gnugnutls
1.1.14
gnugnutls
1.1.15
gnugnutls
1.1.16
gnugnutls
1.1.17
gnugnutls
1.1.18
gnugnutls
1.1.19
gnugnutls
1.1.20
gnugnutls
1.1.21
gnugnutls
1.1.22
gnugnutls
1.1.23
gnugnutls
1.2.0
gnugnutls
1.2.1
gnugnutls
1.2.2
gnugnutls
1.2.3
gnugnutls
1.2.4
gnugnutls
1.2.5
gnugnutls
1.2.6
gnugnutls
1.2.7
gnugnutls
1.2.8
gnugnutls
1.2.9
gnugnutls
1.2.10
gnugnutls
1.2.11
gnugnutls
1.3.0
gnugnutls
1.3.1
gnugnutls
1.3.2
gnugnutls
1.3.3
gnugnutls
1.3.4
gnugnutls
1.3.5
gnugnutls
1.4.0
gnugnutls
1.4.1
gnugnutls
1.4.2
gnugnutls
1.4.3
gnugnutls
1.4.4
gnugnutls
1.4.5
gnugnutls
1.5.0
gnugnutls
1.5.1
gnugnutls
1.5.2
gnugnutls
1.5.3
gnugnutls
1.5.4
gnugnutls
1.5.5
gnugnutls
1.6.0
gnugnutls
1.6.1
gnugnutls
1.6.2
gnugnutls
1.6.3
gnugnutls
1.7.0
gnugnutls
1.7.1
gnugnutls
1.7.2
gnugnutls
1.7.3
gnugnutls
1.7.4
gnugnutls
1.7.5
gnugnutls
1.7.6
gnugnutls
1.7.7
gnugnutls
1.7.8
gnugnutls
1.7.9
gnugnutls
1.7.10
gnugnutls
1.7.11
gnugnutls
1.7.12
gnugnutls
1.7.13
gnugnutls
1.7.14
gnugnutls
1.7.15
gnugnutls
1.7.16
gnugnutls
1.7.17
gnugnutls
1.7.18
gnugnutls
1.7.19
gnugnutls
2.0.0
gnugnutls
2.0.1
gnugnutls
2.0.2
gnugnutls
2.0.3
gnugnutls
2.0.4
gnugnutls
2.1.0
gnugnutls
2.1.1
gnugnutls
2.1.2
gnugnutls
2.1.3
gnugnutls
2.1.4
gnugnutls
2.1.5
gnugnutls
2.1.6
gnugnutls
2.1.7
gnugnutls
2.1.8
gnugnutls
2.2.0
gnugnutls
2.2.1
gnugnutls
2.2.2
gnugnutls
2.2.3
gnugnutls
2.2.4
gnugnutls
2.2.5
gnugnutls
2.3.0
gnugnutls
2.3.1
gnugnutls
2.3.2
gnugnutls
2.3.3
gnugnutls
2.3.4
gnugnutls
2.3.5
gnugnutls
2.3.6
gnugnutls
2.3.7
gnugnutls
2.3.8
gnugnutls
2.3.9
gnugnutls
2.3.10
gnugnutls
2.3.11
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnutls12
hardy
dne
gutsy
dne
feisty
dne
dapper
Fixed 1.2.9-2ubuntu1.2
released
gnutls13
hardy
Fixed 2.0.4-1ubuntu2.1
released
gutsy
Fixed 1.6.3-1ubuntu0.1
released
feisty
Fixed 1.4.4-3ubuntu0.1
released
dapper
dne
gnutls26
hardy
dne
gutsy
dne
feisty
dne
dapper
dne
References