CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2008-1948

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0900%
EPSS Percentile5.32th
Published2008年5月21日
Last Modified2026年4月23日

Vulnerability Description

The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate the number of Server Names in a TLS 1.0 Client Hello message during extension handling, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a zero value for the length of Server Names, which leads to a buffer overflow in session resumption data in the pack_security_parameters function, aka GNUTLS-SA-2008-1-1.

Affected Platforms (CPE)

📦
Gnu

Gnutls

= 1.0.18
📦
Gnu

Gnutls

= 1.0.19
📦
Gnu

Gnutls

= 1.0.20
📦
Gnu

Gnutls

= 1.0.21
📦
Gnu

Gnutls

= 1.0.22
📦
Gnu

Gnutls

= 1.0.23
📦
Gnu

Gnutls

= 1.0.24
📦
Gnu

Gnutls

= 1.0.25
📦
Gnu

Gnutls

= 1.1.13
📦
Gnu

Gnutls

= 1.1.14
📦
Gnu

Gnutls

= 1.1.15
📦
Gnu

Gnutls

= 1.1.16
📦
Gnu

Gnutls

= 1.1.17
📦
Gnu

Gnutls

= 1.1.18
📦
Gnu

Gnutls

= 1.1.19
📦
Gnu

Gnutls

= 1.1.20
📦
Gnu

Gnutls

= 1.1.21
📦
Gnu

Gnutls

= 1.1.22
📦
Gnu

Gnutls

= 1.1.23
📦
Gnu

Gnutls

= 1.2.0
📦
Gnu

Gnutls

= 1.2.1
📦
Gnu

Gnutls

= 1.2.2
📦
Gnu

Gnutls

= 1.2.3
📦
Gnu

Gnutls

= 1.2.4
📦
Gnu

Gnutls

= 1.2.5
📦
Gnu

Gnutls

= 1.2.6
📦
Gnu

Gnutls

= 1.2.7
📦
Gnu

Gnutls

= 1.2.8
📦
Gnu

Gnutls

= 1.2.9
📦
Gnu

Gnutls

= 1.2.10
📦
Gnu

Gnutls

= 1.2.11
📦
Gnu

Gnutls

= 1.3.0
📦
Gnu

Gnutls

= 1.3.1
📦
Gnu

Gnutls

= 1.3.2
📦
Gnu

Gnutls

= 1.3.3
📦
Gnu

Gnutls

= 1.3.4
📦
Gnu

Gnutls

= 1.3.5
📦
Gnu

Gnutls

= 1.4.0
📦
Gnu

Gnutls

= 1.4.1
📦
Gnu

Gnutls

= 1.4.2
📦
Gnu

Gnutls

= 1.4.3
📦
Gnu

Gnutls

= 1.4.4
📦
Gnu

Gnutls

= 1.4.5
📦
Gnu

Gnutls

= 1.5.0
📦
Gnu

Gnutls

= 1.5.1
📦
Gnu

Gnutls

= 1.5.2
📦
Gnu

Gnutls

= 1.5.3
📦
Gnu

Gnutls

= 1.5.4
📦
Gnu

Gnutls

= 1.5.5
📦
Gnu

Gnutls

= 1.6.0
📦
Gnu

Gnutls

= 1.6.1
📦
Gnu

Gnutls

= 1.6.2
📦
Gnu

Gnutls

= 1.6.3
📦
Gnu

Gnutls

= 1.7.0
📦
Gnu

Gnutls

= 1.7.1
📦
Gnu

Gnutls

= 1.7.2
📦
Gnu

Gnutls

= 1.7.3
📦
Gnu

Gnutls

= 1.7.4
📦
Gnu

Gnutls

= 1.7.5
📦
Gnu

Gnutls

= 1.7.6
📦
Gnu

Gnutls

= 1.7.7
📦
Gnu

Gnutls

= 1.7.8
📦
Gnu

Gnutls

= 1.7.9
📦
Gnu

Gnutls

= 1.7.10
📦
Gnu

Gnutls

= 1.7.11
📦
Gnu

Gnutls

= 1.7.12
📦
Gnu

Gnutls

= 1.7.13
📦
Gnu

Gnutls

= 1.7.14
📦
Gnu

Gnutls

= 1.7.15
📦
Gnu

Gnutls

= 1.7.16
📦
Gnu

Gnutls

= 1.7.17
📦
Gnu

Gnutls

= 1.7.18
📦
Gnu

Gnutls

= 1.7.19
📦
Gnu

Gnutls

= 2.0.0
📦
Gnu

Gnutls

= 2.0.1
📦
Gnu

Gnutls

= 2.0.2
📦
Gnu

Gnutls

= 2.0.3
📦
Gnu

Gnutls

= 2.0.4
📦
Gnu

Gnutls

= 2.1.0
📦
Gnu

Gnutls

= 2.1.1
📦
Gnu

Gnutls

= 2.1.2
📦
Gnu

Gnutls

= 2.1.3
📦
Gnu

Gnutls

= 2.1.4
📦
Gnu

Gnutls

= 2.1.5
📦
Gnu

Gnutls

= 2.1.6
📦
Gnu

Gnutls

= 2.1.7
📦
Gnu

Gnutls

= 2.1.8
📦
Gnu

Gnutls

= 2.2.0
📦
Gnu

Gnutls

= 2.2.1
📦
Gnu

Gnutls

= 2.2.2
📦
Gnu

Gnutls

= 2.2.3
📦
Gnu

Gnutls

= 2.2.4
📦
Gnu

Gnutls

= 2.2.5
📦
Gnu

Gnutls

= 2.3.0
📦
Gnu

Gnutls

= 2.3.1
📦
Gnu

Gnutls

= 2.3.2
📦
Gnu

Gnutls

= 2.3.3
📦
Gnu

Gnutls

= 2.3.4
📦
Gnu

Gnutls

= 2.3.5
📦
Gnu

Gnutls

= 2.3.6
📦
Gnu

Gnutls

= 2.3.7
📦
Gnu

Gnutls

= 2.3.8
📦
Gnu

Gnutls

= 2.3.9
📦
Gnu

Gnutls

= 2.3.10
📦
Gnu

Gnutls

= 2.3.11

References & Advisories

相關漏洞威脅