CVE-2008-2377
published 2008-08-08CVE-2008-2377: Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows…
PriorityP335high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
5.46%
91.9th percentile
Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9h4r-gpqc-r78x: Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake
ghsa_unreviewed·2022-05-01
CVE-2008-2377 [HIGH] CWE-119 GHSA-9h4r-gpqc-r78x: Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake
Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.
Red Hat
CVE-2008-2377: Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake
vendor_redhat·CVSS 7.6
CVE-2008-2377 [HIGH] CVE-2008-2377: Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake
Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.
Statement: Not vulnerable. This issue did not affect the versions of gnutls as shipped with Red Hat Enterprise Linux 4, or 5.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/2947http://secunia.com/advisories/31505http://www.gnu.org/software/gnutls/security.htmlhttp://www.nabble.com/Details-on-the-gnutls_handshake-local-crash-problem--GNUTLS-SA-2008-2--td18205022.htmlhttp://www.securityfocus.com/bid/30713http://www.vupen.com/english/advisories/2008/2398https://exchange.xforce.ibmcloud.com/vulnerabilities/44486https://issues.rpath.com/browse/RPL-2650http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/2947http://secunia.com/advisories/31505http://www.gnu.org/software/gnutls/security.htmlhttp://www.nabble.com/Details-on-the-gnutls_handshake-local-crash-problem--GNUTLS-SA-2008-2--td18205022.htmlhttp://www.securityfocus.com/bid/30713http://www.vupen.com/english/advisories/2008/2398https://exchange.xforce.ibmcloud.com/vulnerabilities/44486https://issues.rpath.com/browse/RPL-2650
2008-08-08
Published