CVE-2008-1950

Priority
Medium
Description
Integer signedness error in the _gnutls_ciphertext2compressed function in
lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote
attackers to cause a denial of service (buffer over-read and crash) via a
certain integer value in the Random field in an encrypted Client Hello
message within a TLS record with an invalid Record Length, which leads to
an invalid cipher padding length, aka GNUTLS-SA-2008-1-3.
References
Assigned-to
kees
Package
Upstream:released (2.2.5)
Package
Upstream:needs-triage
Package
Upstream:needs-triage
More Information

Updated: 2016-03-23 03:31:17 UTC (commit 10817)