Oval Definition:oval:org.mitre.oval:def:22264
Revision Date:2014-05-26Version:25
Title:ELSA-2008:0489: gnutls security update (Critical)
Description:Integer signedness error in the _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote attackers to cause a denial of service (buffer over-read and crash) via a certain integer value in the Random field in an encrypted Client Hello message within a TLS record with an invalid Record Length, which leads to an invalid cipher padding length, aka GNUTLS-SA-2008-1-3.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-1948
CVE-2008-1949
CVE-2008-1950
ELSA-2008:0489-01
Platform(s):Oracle Linux 5
Product(s):gnutls
Definition Synopsis
  • Oracle Linux 5.x
  • AND rpm test
  • gnutls-utils is earlier than 0:1.4.1-3.el5_1
  • OR gnutls-devel is earlier than 0:1.4.1-3.el5_1
  • OR gnutls is earlier than 0:1.4.1-3.el5_1
  • BACK