Loading...
Loading...
The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, which allows remote attackers to cause a denial of service (NULL dereference and crash) via a TLS message containing multiple Client Hello messages, aka GNUTLS-SA-2008-1-2.
May 21, 2008
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2008-1949
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.