GnutlsApplication · Gnu

CVE-2008-1948

HIGH · 10.0 CVSS v2.0 Published 2008-05-21
Patch available
A vendor patch is available. No clean upgrade release — apply the published patch.
See remediation →
100/100
Remediation priority · Urgent
Public exploit Remotely reachable No privileges Zero-click Patch available

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate the number of Server Names in a TLS 1.0 Client Hello message during extension handling, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a zero value for the length of Server Names, which leads to a buffer overflow in session resumption data in the pack_security_parameters function, aka GNUTLS-SA-2008-1-1.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis
How this class of weakness works · CWE-189

A legacy NVD category grouping numeric mistakes — overflows, truncation, sign errors — where a miscalculated value goes on to drive a dangerous decision such as a memory allocation or a bounds check. It is a bucket rather than one specific bug. Remediation is checked arithmetic and validating any computed size or index before it is used.

General guidance for the numeric errors class — the official description and references above are authoritative for this specific CVE. Want a bespoke review and a reviewed fix? Ask our team →

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
GnutlsApplication
Affected:= 1.0.18= 1.0.19= 1.0.20= 1.0.21= 1.0.22= 1.0.23= 1.0.24= 1.0.25= 1.1.13= 1.1.14= 1.1.15= 1.1.16

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete

AV:N/AC:L/Au:N/C:C/I:C/A:C

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Patch available Apply the vendor patch
Vendor patch www.openwall.com →
Recommended fix High confidence

GnuTLS 2.2.4 or later (or latest 2.x/3.x stable release available for your distribution)

  1. 1. Identify the current GnuTLS version installed on the system using: rpm -q gnutls or dpkg -l gnutls or gnutls-cli --version
  2. 2. For Debian/Ubuntu: Run 'apt-get update && apt-get install gnutls' to upgrade to the latest available version
  3. 3. For Red Hat/CentOS: Run 'yum update gnutls' to apply the latest security updates
  4. 4. For SUSE: Run 'zypper update gnutls' to apply available patches
  5. 5. After upgrading, verify the new version is installed: gnutls-cli --version
  6. 6. Restart any services that depend on GnuTLS to ensure the new library is loaded
Caveat Upgrading from GnuTLS 1.0.x to 2.x is a major version jump that may introduce API/ABI changes; applications using GnuTLS may require recompilation and testing

Generated from the published advisory — verify against the referenced sources before acting.

We can apply and verify the patch for your build — typical engagement from $1,950. Get the patch applied

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2008-1948 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2008-1948 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data