Description
The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, which allows remote attackers to cause a denial of service (NULL dereference and crash) via a TLS message containing multiple Client Hello messages, aka GNUTLS-SA-2008-1-2.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1581-1 | New gnutls13 packages fix potential code execution |
Ubuntu USN |
USN-613-1 | GnuTLS vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T08:41:00.207Z
Reserved: 2008-04-24T00:00:00.000Z
Link: CVE-2008-1949
No data.
Status : Modified
Published: 2008-05-21T13:24:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2008-1949
OpenCVE Enrichment
No data.
Debian DSA
Ubuntu USN