PT-2008-6946 · Gnutls+1 · Gnutls+1

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2008-1949

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions gnutls versions prior to 2.2.5 gnutls-32bit (affected versions not specified) gnutls-64bit (affected versions not specified) gnutls-devel (affected versions not specified) gnutls-devel-32bit (affected versions not specified) gnutls-devel-64bit (affected versions not specified) gnutls-debuginfo (affected versions not specified) gnutls-x86 (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the gnutls package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The gnutls recv client kx message function in lib/gnutls kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, allowing remote attackers to cause a denial of service via a TLS message containing multiple Client Hello messages.
Recommendations As a temporary workaround, consider disabling the gnutls recv client kx message function until a patch is available. Restrict access to the vulnerable gnutls package to minimize the risk of exploitation. Avoid using the gnutls package until the issue is resolved. For versions prior to 2.2.5, update to a version that contains the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability for the following: gnutls-32bit, gnutls-64bit, gnutls-devel, gnutls-devel-32bit, gnutls-devel-64bit, gnutls-debuginfo, gnutls-x86.

Exploit

Correção

DoS

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04152
BDU:2015-04153
BDU:2015-04154
BDU:2015-04155
BDU:2015-05018
BDU:2015-05019
BDU:2015-05020
BDU:2015-05021
BDU:2015-05022
BDU:2015-05023
BDU:2015-09642
CVE-2008-1949
DSA-1581-1
OPENSUSE-SU-2024:10801-1
RHSA-2008:0489
RHSA-2008:0492
RHSA-2008_0489
RHSA-2008_0492

Produtos afetados

Red Hat
Gnutls