CVE Vulnerabilities

CVE-2008-1950

Published: May 21, 2008 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Integer signedness error in the _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote attackers to cause a denial of service (buffer over-read and crash) via a certain integer value in the Random field in an encrypted Client Hello message within a TLS record with an invalid Record Length, which leads to an invalid cipher padding length, aka GNUTLS-SA-2008-1-3.

Affected Software

Name Vendor Start Version End Version
Gnutls Gnu 1.0.18 (including) 1.0.18 (including)
Gnutls Gnu 1.0.19 (including) 1.0.19 (including)
Gnutls Gnu 1.0.20 (including) 1.0.20 (including)
Gnutls Gnu 1.0.21 (including) 1.0.21 (including)
Gnutls Gnu 1.0.22 (including) 1.0.22 (including)
Gnutls Gnu 1.0.23 (including) 1.0.23 (including)
Gnutls Gnu 1.0.24 (including) 1.0.24 (including)
Gnutls Gnu 1.0.25 (including) 1.0.25 (including)
Gnutls Gnu 1.1.13 (including) 1.1.13 (including)
Gnutls Gnu 1.1.14 (including) 1.1.14 (including)
Gnutls Gnu 1.1.15 (including) 1.1.15 (including)
Gnutls Gnu 1.1.16 (including) 1.1.16 (including)
Gnutls Gnu 1.1.17 (including) 1.1.17 (including)
Gnutls Gnu 1.1.18 (including) 1.1.18 (including)
Gnutls Gnu 1.1.19 (including) 1.1.19 (including)
Gnutls Gnu 1.1.20 (including) 1.1.20 (including)
Gnutls Gnu 1.1.21 (including) 1.1.21 (including)
Gnutls Gnu 1.1.22 (including) 1.1.22 (including)
Gnutls Gnu 1.1.23 (including) 1.1.23 (including)
Gnutls Gnu 1.2.0 (including) 1.2.0 (including)
Gnutls Gnu 1.2.1 (including) 1.2.1 (including)
Gnutls Gnu 1.2.2 (including) 1.2.2 (including)
Gnutls Gnu 1.2.3 (including) 1.2.3 (including)
Gnutls Gnu 1.2.4 (including) 1.2.4 (including)
Gnutls Gnu 1.2.5 (including) 1.2.5 (including)
Gnutls Gnu 1.2.6 (including) 1.2.6 (including)
Gnutls Gnu 1.2.7 (including) 1.2.7 (including)
Gnutls Gnu 1.2.8 (including) 1.2.8 (including)
Gnutls Gnu 1.2.9 (including) 1.2.9 (including)
Gnutls Gnu 1.2.10 (including) 1.2.10 (including)
Gnutls Gnu 1.2.11 (including) 1.2.11 (including)
Gnutls Gnu 1.3.0 (including) 1.3.0 (including)
Gnutls Gnu 1.3.1 (including) 1.3.1 (including)
Gnutls Gnu 1.3.2 (including) 1.3.2 (including)
Gnutls Gnu 1.3.3 (including) 1.3.3 (including)
Gnutls Gnu 1.3.4 (including) 1.3.4 (including)
Gnutls Gnu 1.3.5 (including) 1.3.5 (including)
Gnutls Gnu 1.4.0 (including) 1.4.0 (including)
Gnutls Gnu 1.4.1 (including) 1.4.1 (including)
Gnutls Gnu 1.4.2 (including) 1.4.2 (including)
Gnutls Gnu 1.4.3 (including) 1.4.3 (including)
Gnutls Gnu 1.4.4 (including) 1.4.4 (including)
Gnutls Gnu 1.4.5 (including) 1.4.5 (including)
Gnutls Gnu 1.5.0 (including) 1.5.0 (including)
Gnutls Gnu 1.5.1 (including) 1.5.1 (including)
Gnutls Gnu 1.5.2 (including) 1.5.2 (including)
Gnutls Gnu 1.5.3 (including) 1.5.3 (including)
Gnutls Gnu 1.5.4 (including) 1.5.4 (including)
Gnutls Gnu 1.5.5 (including) 1.5.5 (including)
Gnutls Gnu 1.6.0 (including) 1.6.0 (including)
Gnutls Gnu 1.6.1 (including) 1.6.1 (including)
Gnutls Gnu 1.6.2 (including) 1.6.2 (including)
Gnutls Gnu 1.6.3 (including) 1.6.3 (including)
Gnutls Gnu 1.7.0 (including) 1.7.0 (including)
Gnutls Gnu 1.7.1 (including) 1.7.1 (including)
Gnutls Gnu 1.7.2 (including) 1.7.2 (including)
Gnutls Gnu 1.7.3 (including) 1.7.3 (including)
Gnutls Gnu 1.7.4 (including) 1.7.4 (including)
Gnutls Gnu 1.7.5 (including) 1.7.5 (including)
Gnutls Gnu 1.7.6 (including) 1.7.6 (including)
Gnutls Gnu 1.7.7 (including) 1.7.7 (including)
Gnutls Gnu 1.7.8 (including) 1.7.8 (including)
Gnutls Gnu 1.7.9 (including) 1.7.9 (including)
Gnutls Gnu 1.7.10 (including) 1.7.10 (including)
Gnutls Gnu 1.7.11 (including) 1.7.11 (including)
Gnutls Gnu 1.7.12 (including) 1.7.12 (including)
Gnutls Gnu 1.7.13 (including) 1.7.13 (including)
Gnutls Gnu 1.7.14 (including) 1.7.14 (including)
Gnutls Gnu 1.7.15 (including) 1.7.15 (including)
Gnutls Gnu 1.7.16 (including) 1.7.16 (including)
Gnutls Gnu 1.7.17 (including) 1.7.17 (including)
Gnutls Gnu 1.7.18 (including) 1.7.18 (including)
Gnutls Gnu 1.7.19 (including) 1.7.19 (including)
Gnutls Gnu 2.0.0 (including) 2.0.0 (including)
Gnutls Gnu 2.0.1 (including) 2.0.1 (including)
Gnutls Gnu 2.0.2 (including) 2.0.2 (including)
Gnutls Gnu 2.0.3 (including) 2.0.3 (including)
Gnutls Gnu 2.0.4 (including) 2.0.4 (including)
Gnutls Gnu 2.1.0 (including) 2.1.0 (including)
Gnutls Gnu 2.1.1 (including) 2.1.1 (including)
Gnutls Gnu 2.1.2 (including) 2.1.2 (including)
Gnutls Gnu 2.1.3 (including) 2.1.3 (including)
Gnutls Gnu 2.1.4 (including) 2.1.4 (including)
Gnutls Gnu 2.1.5 (including) 2.1.5 (including)
Gnutls Gnu 2.1.6 (including) 2.1.6 (including)
Gnutls Gnu 2.1.7 (including) 2.1.7 (including)
Gnutls Gnu 2.1.8 (including) 2.1.8 (including)
Gnutls Gnu 2.2.0 (including) 2.2.0 (including)
Gnutls Gnu 2.2.1 (including) 2.2.1 (including)
Gnutls Gnu 2.2.2 (including) 2.2.2 (including)
Gnutls Gnu 2.2.3 (including) 2.2.3 (including)
Gnutls Gnu 2.2.4 (including) 2.2.4 (including)
Gnutls Gnu 2.2.5 (including) 2.2.5 (including)
Gnutls Gnu 2.3.0 (including) 2.3.0 (including)
Gnutls Gnu 2.3.1 (including) 2.3.1 (including)
Gnutls Gnu 2.3.2 (including) 2.3.2 (including)
Gnutls Gnu 2.3.3 (including) 2.3.3 (including)
Gnutls Gnu 2.3.4 (including) 2.3.4 (including)
Gnutls Gnu 2.3.5 (including) 2.3.5 (including)
Gnutls Gnu 2.3.6 (including) 2.3.6 (including)
Gnutls Gnu 2.3.7 (including) 2.3.7 (including)
Gnutls Gnu 2.3.8 (including) 2.3.8 (including)
Gnutls Gnu 2.3.9 (including) 2.3.9 (including)
Gnutls Gnu 2.3.10 (including) 2.3.10 (including)
Gnutls Gnu 2.3.11 (including) 2.3.11 (including)
Red Hat Enterprise Linux 4 RedHat gnutls-0:1.0.20-4.el4_6 *
Red Hat Enterprise Linux 5 RedHat gnutls-0:1.4.1-3.el5_1 *
Gnutls12 Ubuntu dapper *
Gnutls13 Ubuntu devel *
Gnutls13 Ubuntu feisty *
Gnutls13 Ubuntu gutsy *
Gnutls13 Ubuntu hardy *
Gnutls26 Ubuntu upstream *

References