CVE-2016-4579Improper Input Validation in Libksba

Severity
7.5HIGHNVD
EPSS
1.2%
top 21.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 13

Description

Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

debiandebian/libksba< libksba 1.3.4-3 (bookworm)
Debiangnupg/libksba< 1.3.4-3+3
Ubuntugnupg/libksba< 1.3.0-3ubuntu0.14.04.2+1
NVDgnupg/libksba1.3.3
NVDopensuse/leap42.1

Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-rjw4-277h-vv44: Libksba before 12022-05-13
OSV
CVE-2016-4579: Libksba before 12016-06-13
OSV
libksba vulnerabilities2016-05-17

📋Vendor Advisories

3
Ubuntu
Libksba vulnerabilities2016-05-17
Red Hat
libksba: Out-of-bounds read in _ksba_ber_parse_tl2016-05-10
Debian
CVE-2016-4579: libksba - Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-o...2016

💬Community

2
Bugzilla
CVE-2016-4579 libksba: Out-of-bounds read in _ksba_ber_parse_tl2016-05-12
Bugzilla
CVE-2016-4574 CVE-2016-4579 libksba: various flaws [fedora-all]2016-05-10
CVE-2016-4579 — Improper Input Validation in Libksba | cvebase