CVE-2008-1949

GnuTLS <2.2.4 - DoS

Title source: llm

Description

The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, which allows remote attackers to cause a denial of service (NULL dereference and crash) via a TLS message containing multiple Client Hello messages, aka GNUTLS-SA-2008-1-2.

Scores

EPSS 0.1517
EPSS Percentile 94.5%

Classification

CWE
CWE-287
Status draft

Affected Products (50)

gnu/gnutls
gnu/gnutls
gnu/gnutls
gnu/gnutls
gnu/gnutls
gnu/gnutls
gnu/gnutls
gnu/gnutls
gnu/gnutls
gnu/gnutls
gnu/gnutls
gnu/gnutls
gnu/gnutls
gnu/gnutls
gnu/gnutls
... and 35 more

Timeline

Published May 21, 2008
Tracked Since Feb 18, 2026