CVE-2016-4356Improper Restriction of Operations within the Bounds of a Memory Buffer in Libksba

Severity
7.5HIGHNVD
EPSS
1.0%
top 23.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 13

Description

The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

debiandebian/libksba< libksba 1.3.4-3 (bookworm)+1
Debiangnupg/libksba< 1.3.3-1+7
Ubuntugnupg/libksba< 1.3.0-3ubuntu0.14.04.2+1
NVDgnupg/libksba1.3.2+1
NVDopensuse/leap42.1

Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

5
GHSA
GHSA-mhm6-qhc6-f9f7: The append_utf8_value function in the DN decoder (dn2022-05-13
GHSA
GHSA-986h-5j8j-hgfc: Off-by-one error in the append_utf8_value function in the DN decoder (dn2022-05-13
OSV
CVE-2016-4356: The append_utf8_value function in the DN decoder (dn2016-06-13
OSV
CVE-2016-4574: Off-by-one error in the append_utf8_value function in the DN decoder (dn2016-06-13
OSV
libksba vulnerabilities2016-05-17

📋Vendor Advisories

5
Ubuntu
Libksba vulnerabilities2016-05-17
Red Hat
libksba: Incomplete fix for CVE-2016-43562016-05-10
Debian
CVE-2016-4574: libksba - Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in L...2016
Debian
CVE-2016-4356: libksba - The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 ...2016
Red Hat
libksba: encoding of invalid utf-8 strings in DN decoder src/dn.c (append_quoted, append_atv)2015-04-08

💬Community

3
Bugzilla
CVE-2016-4574 libksba: Incomplete fix for CVE-2016-43562016-05-10
Bugzilla
CVE-2016-4353 CVE-2016-4354 CVE-2016-4355 CVE-2016-4356 libksba: various flaws [fedora-all]2015-04-13
Bugzilla
CVE-2016-4356 libksba: encoding of invalid utf-8 strings in DN decoder src/dn.c (append_quoted, append_atv)2015-04-13