Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-2377
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-2377

Description:
Use after free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/44486

SAID
  Secunia Advisory: SA31505

MLIST
  http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/2947
  http://www.nabble.com/Details-on-the-gnutls_handshake-local-crash-problem--GNUTLS-SA-2008-2--td18205022.html

CONFIRM
  http://www.gnu.org/software/gnutls/security.html

BID
  30713


Return to the previous page.