Input validation error in GnuTLS - CVE-2008-2377
Published: August 8, 2008 / Updated: April 30, 2026
GnuTLS
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service on the client side.
The vulnerability exists due to improper input validation in the GnuTLS client-side processing of server responses when handling crafted responses from a server. A remote attacker can send a specially crafted server response to cause a denial of service on the client side.
Reports indicate the issue may be exploitable by hostile servers.