Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-2377

Опубликовано: 08 авг. 2008
Источник: nvd
CVSS2: 7.6
EPSS Средний

Описание

Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnu:gnutls:2.3.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:2.3.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:2.3.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:2.3.8:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:2.3.9:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:2.4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.12134
Средний

7.6 High

CVSS2

Дефекты

CWE-119

Связанные уязвимости

ubuntu
больше 17 лет назад

Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.

debian
больше 17 лет назад

Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_cle ...

github
больше 3 лет назад

Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.

EPSS

Процентиль: 94%
0.12134
Средний

7.6 High

CVSS2

Дефекты

CWE-119