CVE-2008-1949: Critical severity gnutls vulnerability
The gnutlsrecvclientkxmessage function in lib/gnutlskx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, which allows remote attackers to cause a denial of service (NULL dereference and crash) via a TLS message containing multiple Client Hello messages, aka GNUTLS-SA-2008-1-2.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1949?
CVE-2008-1949 has a severity rating that indicates it can lead to a denial of service due to NULL dereference.
How do I fix CVE-2008-1949?
To fix CVE-2008-1949, upgrade to GnuTLS version 2.2.4 or later.
What does CVE-2008-1949 affect?
CVE-2008-1949 affects multiple versions of GnuTLS prior to version 2.2.4.
What is the potential impact of CVE-2008-1949?
The potential impact of CVE-2008-1949 includes causing a denial of service through the improper handling of Client Hello messages.
Is CVE-2008-1949 easy to exploit?
Yes, CVE-2008-1949 can be exploited remotely by sending crafted TLS messages.