A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3153-1 | libksba security update |
Debian DSA |
DSA-5255-1 | libksba security update |
EUVD |
EUVD-2022-42884 | A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment. |
Ubuntu USN |
USN-5688-1 | Libksba vulnerability |
Ubuntu USN |
USN-5688-2 | Libksba vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 08 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-04-08T15:48:31.667Z
Reserved: 2022-10-14T00:00:00.000Z
Link: CVE-2022-3515
Updated: 2024-08-03T01:14:02.956Z
Status : Modified
Published: 2023-01-12T15:15:10.187
Modified: 2025-04-08T16:15:19.830
Link: CVE-2022-3515
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN