Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/2947 http://secunia.com/advisories/31505/
http://www.vuxml.org/freebsd/d864a0a7-6f27-11dd-acfe-00104b9e1a4a.html
Insight
The following package is affected: gnutls
CVE-2008-2377
Use after free vulnerability in the
_gnutls_handshake_hash_buffers_clear function in
lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.
Severity
Classification
-
CVE CVE-2008-2377 -
CVSS Base Score: 7.6
AV:N/AC:H/Au:N/C:C/I:C/A:C
Related Vulnerabilities