CVE-2008-1950 describes an integer signedness error in the _gnutls_ciphertext2compressed function within the libgnutls library, affecting GnuTLS versions prior to 2.2.4. This flaw allows remote attackers to trigger a denial of service (buffer over-read and crash) by sending a crafted Client Hello message with an invalid Record Length, leading to an incorrect cipher padding length. The vulnerability has a CVSS score of 5.0, indicating a medium severity with a network-based attack vector, low attack complexity, and potential for partial availability impact. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, with only one mention and one article identified, neither of which suggests widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.18CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.18:*:*:*:*:*:*:* | ||
1.0.19CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.19:*:*:*:*:*:*:* | ||
1.0.20CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.20:*:*:*:*:*:*:* | ||
1.0.21CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.21:*:*:*:*:*:*:* | ||
1.0.22CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.22:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.