PT-2008-6947 · Gnu+1 · Gnutls+1

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2008-1950

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions gnutls versions prior to 2.2.5 gnutls-32bit (affected versions not specified) gnutls-64bit (affected versions not specified) gnutls-devel (affected versions not specified) gnutls-devel-32bit (affected versions not specified) gnutls-devel-64bit (affected versions not specified) gnutls-debuginfo (affected versions not specified) gnutls-x86 (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the gnutls package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely, potentially causing a denial of service due to a buffer over-read and crash. The vulnerabilities are caused by an integer signedness error in the gnutls ciphertext2compressed function.
Recommendations For gnutls versions prior to 2.2.5, update to version 2.2.5 or later to resolve the issue. For gnutls-32bit, gnutls-64bit, gnutls-devel, gnutls-devel-32bit, gnutls-devel-64bit, gnutls-debuginfo, and gnutls-x86, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04152
BDU:2015-04153
BDU:2015-04154
BDU:2015-04155
BDU:2015-05018
BDU:2015-05019
BDU:2015-05020
BDU:2015-05021
BDU:2015-05022
BDU:2015-05023
BDU:2015-09642
CVE-2008-1950
DSA-1581-1
OPENSUSE-SU-2024:10801-1
RHSA-2008:0489
RHSA-2008:0492
RHSA-2008_0489
RHSA-2008_0492

Produtos afetados

Red Hat
Gnutls