| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.61447 |
| Category: | FreeBSD Local Security Checks |
| Title: | FreeBSD Ports: gnutls |
| Summary: | FreeBSD Ports: gnutls |
| Description: | The remote host is missing an update to the system as announced in the referenced advisory. The following package is affected: gnutls CVE-2008-2377 Use after free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle. Solution: Update your system with the appropriate patches or software upgrades. http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/2947 http://secunia.com/advisories/31505/ http://www.vuxml.org/freebsd/d864a0a7-6f27-11dd-acfe-00104b9e1a4a.html |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-2377 http://www.nabble.com/Details-on-the-gnutls_handshake-local-crash-problem--GNUTLS-SA-2008-2--td18205022.html http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/2947 BugTraq ID: 30713 http://www.securityfocus.com/bid/30713 http://www.vupen.com/english/advisories/2008/2398 http://secunia.com/advisories/31505 XForce ISS Database: gnutls-gnutlshandshake-code-execution(44486) http://xforce.iss.net/xforce/xfdb/44486 |
| Copyright | Copyright (c) 2008 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|