CVE-2008-1948 describes a critical buffer overflow vulnerability in GnuTLS versions prior to 2.2.4, specifically within the _gnutls_server_name_recv_params function. This flaw allows remote attackers to trigger a denial of service (crash) or potentially execute arbitrary code by sending a crafted TLS 1.0 Client Hello message with a zero-length Server Names field. With a CVSS score of 10.0, this vulnerability is extremely severe, indicating a network-exploitable attack with low complexity, requiring no authentication, and leading to complete compromise of confidentiality, integrity, and availability. While the EPSS score is relatively low, its FAUCET Risk Score of 94/100 highlights its significant danger. There is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB, and community discussion and media coverage are minimal, suggesting it has not garnered widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.18CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.18:*:*:*:*:*:*:* | ||
1.0.19CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.19:*:*:*:*:*:*:* | ||
1.0.20CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.20:*:*:*:*:*:*:* | ||
1.0.21CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.21:*:*:*:*:*:*:* | ||
1.0.22CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.22:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.