CVE-2006-5111
published 2006-10-03CVE-2006-5111: The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the newpg package on SUSE LINUX, allows attackers to cause a denial of service…
PriorityP414medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.83%
76.5th percentile
The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the newpg package on SUSE LINUX, allows attackers to cause a denial of service (application crash) via a malformed X.509 certificate in a signature.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libksba | < libksba 0.9.14-1 (bookworm) | libksba 0.9.14-1 (bookworm) |
| gnupg | libksba | >= 0 < 0.9.14-1 | 0.9.14-1 |
| gnupg | libksba | >= 0 < 0.9.14-1 | 0.9.14-1 |
| gnupg | libksba | >= 0 < 0.9.14-1 | 0.9.14-1 |
| gnupg | libksba | >= 0 < 0.9.14-1 | 0.9.14-1 |
| libksba_library | libksba_library | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hh6w-9c5q-qw82: The libksba library 0
ghsa_unreviewed·2022-05-01
CVE-2006-5111 [MEDIUM] GHSA-hh6w-9c5q-qw82: The libksba library 0
The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the newpg package on SUSE LINUX, allows attackers to cause a denial of service (application crash) via a malformed X.509 certificate in a signature.
OSV
CVE-2006-5111: The libksba library 0
osv·2006-10-03·CVSS 5.0
CVE-2006-5111 [MEDIUM] CVE-2006-5111: The libksba library 0
The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the newpg package on SUSE LINUX, allows attackers to cause a denial of service (application crash) via a malformed X.509 certificate in a signature.
Ubuntu
libksba vulnerability
vendor_ubuntu·2006-10-16
CVE-2006-5111 libksba vulnerability
Title: libksba vulnerability
Summary: libksba vulnerability
A parsing failure was discovered in the handling of X.509 certificates
that contained extra trailing data. Malformed or malicious certificates
could cause services using libksba to crash, potentially creating a
denial of service.
Instructions: After a standard system upgrade you need to restart your session to
effect the necessary changes.
Debian
CVE-2006-5111: libksba - The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the ...
vendor_debian·2006·CVSS 5.0
CVE-2006-5111 [MEDIUM] CVE-2006-5111: libksba - The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the ...
The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the newpg package on SUSE LINUX, allows attackers to cause a denial of service (application crash) via a malformed X.509 certificate in a signature.
Scope: local
bookworm: resolved (fixed in 0.9.14-1)
bullseye: resolved (fixed in 0.9.14-1)
forky: resolved (fixed in 0.9.14-1)
sid: resolved (fixed in 0.9.14-1)
trixie: resolved (fixed in 0.9.14-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/22423http://secunia.com/advisories/22445http://secunia.com/advisories/22473http://www.mandriva.com/security/advisories?name=MDKSA-2006:183http://www.novell.com/linux/download/updates/101_x86_64.htmlhttp://www.novell.com/linux/security/advisories/2006_23_sr.htmlhttp://www.securityfocus.com/bid/20565http://www.ubuntu.com/usn/usn-365-1https://exchange.xforce.ibmcloud.com/vulnerabilities/29621http://secunia.com/advisories/22423http://secunia.com/advisories/22445http://secunia.com/advisories/22473http://www.mandriva.com/security/advisories?name=MDKSA-2006:183http://www.novell.com/linux/download/updates/101_x86_64.htmlhttp://www.novell.com/linux/security/advisories/2006_23_sr.htmlhttp://www.securityfocus.com/bid/20565http://www.ubuntu.com/usn/usn-365-1https://exchange.xforce.ibmcloud.com/vulnerabilities/29621
2006-10-03
Published