Unrated severityNVD Advisory· Published Aug 8, 2008· Updated Jun 16, 2026
CVE-2008-2377
CVE-2008-2377
Description
Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:gnu:gnutls:2.3.5:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gnu:gnutls:2.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:2.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:2.3.7:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:2.3.8:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:2.3.9:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:2.4.0:*:*:*:*:*:*:*
- Range: 2.3.5 - 2.4.0
Patches
Vulnerability mechanics
References
8- article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/2947nvdPatch
- www.nabble.com/Details-on-the-gnutls_handshake-local-crash-problem--GNUTLS-SA-2008-2--td18205022.htmlnvdExploit
- secunia.com/advisories/31505nvd
- www.gnu.org/software/gnutls/security.htmlnvd
- www.securityfocus.com/bid/30713nvd
- www.vupen.com/english/advisories/2008/2398nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/44486nvd
- issues.rpath.com/browse/RPL-2650nvd
News mentions
0No linked articles in our index yet.