The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate the number of Server Names in a TLS 1.0 Client Hello message during extension handling, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a zero value for the length of Server Names, which leads to a buffer overflow in session resumption data in the pack_security_parameters function, aka GNUTLS-SA-2008-1-1.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gnutlsUpgrade gnutls-utilsUpgrade gnutls-devel | Dec 1, 2016 | May 21, 2008 |
| Gentoo Linux | — | Upgrade net-libs/gnutls. | Oct 30, 2017 | May 21, 2008 |
| Oracle_linux | — | Upgrade gnutlsUpgrade gnutls-develUpgrade gnutls-utils | Oct 16, 2024 | May 21, 2008 |
| Suse | — | Upgrade libgnutls-extra26Upgrade libgnutls30Upgrade libgnutls-extra-develUpgrade libgnutls26-x86Upgrade gnutlsUpgrade libgnutlsxx-develUpgrade libgnutls26Upgrade libgnutls-develUpgrade libgnutls26-32bitUpgrade libgnutlsxx30Upgrade libgnutls-devel-doc | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libgnutls13Upgrade libgnutls12 | Nov 8, 2024 | May 21, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub