CVE-2008-1950

Priority
Medium
Description
Integer signedness error in the _gnutls_ciphertext2compressed function in
lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote
attackers to cause a denial of service (buffer over-read and crash) via a
certain integer value in the Random field in an encrypted Client Hello
message within a TLS record with an invalid Record Length, which leads to
an invalid cipher padding length, aka GNUTLS-SA-2008-1-3.
References
Assigned-to
kees
Package
Upstream:released (2.2.5)
Package
Upstream:needs-triage
Package
Upstream:needs-triage
More Information

Valid XHTML 1.0 Strict

Updated: 2015-07-29 20:32:34 UTC (commit 9756)