rpm package
opensuse/libksba&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/libksba&distro=openSUSE%20Tumbleweed
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-3515 | — | < 1.6.2-1.1 | 1.6.2-1.1 | Jan 12, 2023 | A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment. | ||
| CVE-2022-47629 | — | < 1.6.3-1.1 | 1.6.3-1.1 | Dec 20, 2022 | Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser. | ||
| CVE-2016-4579 | Hig | 7.5 | < 1.3.5-1.3 | 1.3.5-1.3 | Jun 13, 2016 | Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl." | |
| CVE-2016-4574 | Hig | 7.5 | < 1.3.5-1.3 | 1.3.5-1.3 | Jun 13, 2016 | Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016- | |
| CVE-2014-9087 | — | < 1.3.5-1.3 | 1.3.5-1.3 | Dec 1, 2014 | Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow. |
- CVE-2022-3515Jan 12, 2023affected < 1.6.2-1.1fixed 1.6.2-1.1
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
- CVE-2022-47629Dec 20, 2022affected < 1.6.3-1.1fixed 1.6.3-1.1
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
- affected < 1.3.5-1.3fixed 1.3.5-1.3
Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."
- affected < 1.3.5-1.3fixed 1.3.5-1.3
Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-
- CVE-2014-9087Dec 1, 2014affected < 1.3.5-1.3fixed 1.3.5-1.3
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.