CVE-2008-1950

Priority
Medium
Description
Integer signedness error in the _gnutls_ciphertext2compressed function in
lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote
attackers to cause a denial of service (buffer over-read and crash) via a
certain integer value in the Random field in an encrypted Client Hello
message within a TLS record with an invalid Record Length, which leads to
an invalid cipher padding length, aka GNUTLS-SA-2008-1-3.
References
Assigned-to
kees
Package
Upstream:released (2.2.5)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):released (2.0.4-1ubuntu2.1)
More Information

Valid XHTML 1.0 Strict

Updated: 2012-06-01 15:18:46 UTC (commit 5347)