CVE Vulnerabilities

CVE-2008-1949

Improper Authentication

Published: May 21, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, which allows remote attackers to cause a denial of service (NULL dereference and crash) via a TLS message containing multiple Client Hello messages, aka GNUTLS-SA-2008-1-2.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
GnutlsGnu1.0.18 (including)1.0.18 (including)
GnutlsGnu1.0.19 (including)1.0.19 (including)
GnutlsGnu1.0.20 (including)1.0.20 (including)
GnutlsGnu1.0.21 (including)1.0.21 (including)
GnutlsGnu1.0.22 (including)1.0.22 (including)
GnutlsGnu1.0.23 (including)1.0.23 (including)
GnutlsGnu1.0.24 (including)1.0.24 (including)
GnutlsGnu1.0.25 (including)1.0.25 (including)
GnutlsGnu1.1.13 (including)1.1.13 (including)
GnutlsGnu1.1.14 (including)1.1.14 (including)
GnutlsGnu1.1.15 (including)1.1.15 (including)
GnutlsGnu1.1.16 (including)1.1.16 (including)
GnutlsGnu1.1.17 (including)1.1.17 (including)
GnutlsGnu1.1.18 (including)1.1.18 (including)
GnutlsGnu1.1.19 (including)1.1.19 (including)
GnutlsGnu1.1.20 (including)1.1.20 (including)
GnutlsGnu1.1.21 (including)1.1.21 (including)
GnutlsGnu1.1.22 (including)1.1.22 (including)
GnutlsGnu1.1.23 (including)1.1.23 (including)
GnutlsGnu1.2.0 (including)1.2.0 (including)
GnutlsGnu1.2.1 (including)1.2.1 (including)
GnutlsGnu1.2.2 (including)1.2.2 (including)
GnutlsGnu1.2.3 (including)1.2.3 (including)
GnutlsGnu1.2.4 (including)1.2.4 (including)
GnutlsGnu1.2.5 (including)1.2.5 (including)
GnutlsGnu1.2.6 (including)1.2.6 (including)
GnutlsGnu1.2.7 (including)1.2.7 (including)
GnutlsGnu1.2.8 (including)1.2.8 (including)
GnutlsGnu1.2.9 (including)1.2.9 (including)
GnutlsGnu1.2.10 (including)1.2.10 (including)
GnutlsGnu1.2.11 (including)1.2.11 (including)
GnutlsGnu1.3.0 (including)1.3.0 (including)
GnutlsGnu1.3.1 (including)1.3.1 (including)
GnutlsGnu1.3.2 (including)1.3.2 (including)
GnutlsGnu1.3.3 (including)1.3.3 (including)
GnutlsGnu1.3.4 (including)1.3.4 (including)
GnutlsGnu1.3.5 (including)1.3.5 (including)
GnutlsGnu1.4.0 (including)1.4.0 (including)
GnutlsGnu1.4.1 (including)1.4.1 (including)
GnutlsGnu1.4.2 (including)1.4.2 (including)
GnutlsGnu1.4.3 (including)1.4.3 (including)
GnutlsGnu1.4.4 (including)1.4.4 (including)
GnutlsGnu1.4.5 (including)1.4.5 (including)
GnutlsGnu1.5.0 (including)1.5.0 (including)
GnutlsGnu1.5.1 (including)1.5.1 (including)
GnutlsGnu1.5.2 (including)1.5.2 (including)
GnutlsGnu1.5.3 (including)1.5.3 (including)
GnutlsGnu1.5.4 (including)1.5.4 (including)
GnutlsGnu1.5.5 (including)1.5.5 (including)
GnutlsGnu1.6.0 (including)1.6.0 (including)
GnutlsGnu1.6.1 (including)1.6.1 (including)
GnutlsGnu1.6.2 (including)1.6.2 (including)
GnutlsGnu1.6.3 (including)1.6.3 (including)
GnutlsGnu1.7.0 (including)1.7.0 (including)
GnutlsGnu1.7.1 (including)1.7.1 (including)
GnutlsGnu1.7.2 (including)1.7.2 (including)
GnutlsGnu1.7.3 (including)1.7.3 (including)
GnutlsGnu1.7.4 (including)1.7.4 (including)
GnutlsGnu1.7.5 (including)1.7.5 (including)
GnutlsGnu1.7.6 (including)1.7.6 (including)
GnutlsGnu1.7.7 (including)1.7.7 (including)
GnutlsGnu1.7.8 (including)1.7.8 (including)
GnutlsGnu1.7.9 (including)1.7.9 (including)
GnutlsGnu1.7.10 (including)1.7.10 (including)
GnutlsGnu1.7.11 (including)1.7.11 (including)
GnutlsGnu1.7.12 (including)1.7.12 (including)
GnutlsGnu1.7.13 (including)1.7.13 (including)
GnutlsGnu1.7.14 (including)1.7.14 (including)
GnutlsGnu1.7.15 (including)1.7.15 (including)
GnutlsGnu1.7.16 (including)1.7.16 (including)
GnutlsGnu1.7.17 (including)1.7.17 (including)
GnutlsGnu1.7.18 (including)1.7.18 (including)
GnutlsGnu1.7.19 (including)1.7.19 (including)
GnutlsGnu2.0.0 (including)2.0.0 (including)
GnutlsGnu2.0.1 (including)2.0.1 (including)
GnutlsGnu2.0.2 (including)2.0.2 (including)
GnutlsGnu2.0.3 (including)2.0.3 (including)
GnutlsGnu2.0.4 (including)2.0.4 (including)
GnutlsGnu2.1.0 (including)2.1.0 (including)
GnutlsGnu2.1.1 (including)2.1.1 (including)
GnutlsGnu2.1.2 (including)2.1.2 (including)
GnutlsGnu2.1.3 (including)2.1.3 (including)
GnutlsGnu2.1.4 (including)2.1.4 (including)
GnutlsGnu2.1.5 (including)2.1.5 (including)
GnutlsGnu2.1.6 (including)2.1.6 (including)
GnutlsGnu2.1.7 (including)2.1.7 (including)
GnutlsGnu2.1.8 (including)2.1.8 (including)
GnutlsGnu2.2.0 (including)2.2.0 (including)
GnutlsGnu2.2.1 (including)2.2.1 (including)
GnutlsGnu2.2.2 (including)2.2.2 (including)
GnutlsGnu2.2.3 (including)2.2.3 (including)
GnutlsGnu2.2.4 (including)2.2.4 (including)
GnutlsGnu2.2.5 (including)2.2.5 (including)
GnutlsGnu2.3.0 (including)2.3.0 (including)
GnutlsGnu2.3.1 (including)2.3.1 (including)
GnutlsGnu2.3.2 (including)2.3.2 (including)
GnutlsGnu2.3.3 (including)2.3.3 (including)
GnutlsGnu2.3.4 (including)2.3.4 (including)
GnutlsGnu2.3.5 (including)2.3.5 (including)
GnutlsGnu2.3.6 (including)2.3.6 (including)
GnutlsGnu2.3.7 (including)2.3.7 (including)
GnutlsGnu2.3.8 (including)2.3.8 (including)
GnutlsGnu2.3.9 (including)2.3.9 (including)
GnutlsGnu2.3.10 (including)2.3.10 (including)
GnutlsGnu2.3.11 (including)2.3.11 (including)
Red Hat Enterprise Linux 4RedHatgnutls-0:1.0.20-4.el4_6*
Red Hat Enterprise Linux 5RedHatgnutls-0:1.4.1-3.el5_1*
Gnutls12Ubuntudapper*
Gnutls13Ubuntudevel*
Gnutls13Ubuntufeisty*
Gnutls13Ubuntugutsy*
Gnutls13Ubuntuhardy*
Gnutls26Ubuntuupstream*

Potential Mitigations

References