| /// File Name: | dsa-1581-1.txt | Description:
| Debian Security Advisory 1581-1 - Several remote vulnerabilities have been discovered in GNUTLS, an implementation of the SSL/TLS protocol suite. A pre-authentication heap overflow involving oversized session resumption data may lead to arbitrary code execution. Repeated client hellos may result in a pre-authentication denial of service condition due to a null pointer dereference. Decoding cipher padding with an invalid record length may cause GNUTLS to read memory beyond the end of the received record, leading to a pre-authentication denial of service condition. | | Homepage: | http://www.debian.org/security | | File Size: | 10769 | | Related CVE(s): | CVE-2008-1948, CVE-2008-1950, CVE-2008-1949 | | Last Modified: | May 20 16:42:16 2008 | | MD5 Checksum: | 6e93f5ea4d61f973f00663bbeffaaacd |
|