CVE-2008-1948: Buffer Overflow
The gnutlsservernamerecvparams function in lib/extservername.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate the number of Server Names in a TLS 1.0 Client Hello message during extension handling, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a zero value for the length of Server Names, which leads to a buffer overflow in session resumption data in the packsecurityparameters function, aka GNUTLS-SA-2008-1-1.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1948?
The severity of CVE-2008-1948 is classified as medium, due to its potential to cause a denial of service.
How do I fix CVE-2008-1948?
To fix CVE-2008-1948, upgrade to GnuTLS version 2.2.4 or later.
What software versions are affected by CVE-2008-1948?
CVE-2008-1948 affects GnuTLS versions prior to 2.2.4, including versions 1.0.18 through 1.5.5.
Can CVE-2008-1948 be exploited remotely?
Yes, CVE-2008-1948 can be exploited by remote attackers to trigger a denial of service.
Is CVE-2008-1948 a code execution vulnerability?
No, CVE-2008-1948 is not a code execution vulnerability; it results in denial of service.