GnuPG libksba 1.3.3

CPE Details

GnuPG libksba 1.3.3
1.3.3
2023-05-18
16h05 +00:00
2023-05-18
16h08 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:gnupg:libksba:1.3.3:*:*:*:*:*:*:*

Informations

Vendor

gnupg

Product

libksba

Version

1.3.3

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-3515 2023-01-11 23h00 +00:00 A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
9.8
Critique
CVE-2022-47629 2022-12-19 23h00 +00:00 Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
9.8
Critique
CVE-2016-4574 2016-06-13 17h00 +00:00 Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-4356.
7.5
Haute
CVE-2016-4579 2016-06-13 17h00 +00:00 Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."
7.5
Haute