Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-2377

Опубликовано: 08 авг. 2008
Источник: ubuntu
Приоритет: low
CVSS2: 7.6

Описание

Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.

РелизСтатусПримечание
dapper

not-affected

devel

DNE

feisty

DNE

gutsy

DNE

hardy

DNE

upstream

released

2.4.1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

feisty

not-affected

gutsy

not-affected

hardy

not-affected

upstream

released

2.4.1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

feisty

DNE

gutsy

DNE

hardy

DNE

upstream

released

2.4.1

Показывать по

Ссылки на источники

7.6 High

CVSS2

Связанные уязвимости

nvd
больше 17 лет назад

Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.

debian
больше 17 лет назад

Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_cle ...

github
больше 3 лет назад

Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.

7.6 High

CVSS2

Уязвимость CVE-2008-2377