CVE-2008-1950: Medium severity gnutls vulnerability
Integer signedness error in the gnutlsciphertext2compressed function in lib/gnutlscipher.c in libgnutls in GnuTLS before 2.2.4 allows remote attackers to cause a denial of service (buffer over-read and crash) via a certain integer value in the Random field in an encrypted Client Hello message within a TLS record with an invalid Record Length, which leads to an invalid cipher padding length, aka GNUTLS-SA-2008-1-3.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1950?
The severity of CVE-2008-1950 is considered medium due to the potential for denial of service.
How do I fix CVE-2008-1950?
To fix CVE-2008-1950, you should upgrade to GnuTLS version 2.2.4 or later.
What types of systems are affected by CVE-2008-1950?
CVE-2008-1950 affects various versions of GnuTLS, including versions from 1.0.0 to 2.3.5.
What vulnerabilities does CVE-2008-1950 exploit?
CVE-2008-1950 exploits an integer signedness error resulting in buffer over-read.
Can CVE-2008-1950 be exploited remotely?
Yes, CVE-2008-1950 can be exploited remotely by sending specially crafted Client Hello messages.