CVE-2022-3515
published 2023-01-12CVE-2022-3515: A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.64%
73.6th percentile
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libksba | < libksba 1.6.2-1 (bookworm) | libksba 1.6.2-1 (bookworm) |
| gnupg | gnupg | >= 2.1.0 < 2.2.41 | 2.2.41 |
| gnupg | gnupg | >= 2.3.0 < 2.4.0 | 2.4.0 |
| gnupg | libksba | < 1.6.3 | 1.6.3 |
| gnupg | libksba | — | — |
| gnupg | libksba | >= 0 < 1.5.0-3+deb11u1 | 1.5.0-3+deb11u1 |
| gnupg | libksba | >= 0 < 1.6.2-1 | 1.6.2-1 |
| gnupg | libksba | >= 0 < 1.6.2-1 | 1.6.2-1 |
| gnupg | libksba | >= 0 < 1.6.2-1 | 1.6.2-1 |
| gnupg | vs-desktop | >= 3.1.16 < 3.1.26 | 3.1.26 |
| gpg4win | gpg4win | >= 2.0.0 < 4.1.0 | 4.1.0 |
| msrc | cbl2_gnupg2_2.4.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_gnupg2_2.2.20-4_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_libksba_1.3.5-5_on_cbl_mariner_1.0 | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Microsoft
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specia
vendor_msrc·2023-01-10·CVSS 9.8
CVE-2022-3515 [CRITICAL] CWE-190 A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specia
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application for example a malicious S/MIME attachment.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more i
Ubuntu
Libksba vulnerability
vendor_ubuntu·2022-10-26
CVE-2022-3515 Libksba vulnerability
Title: Libksba vulnerability
Summary: Libksba could be made to crash or run programs if it decoded specially
crafted data.
USN-5688-1 fixed vulnerabilities in Libksba. This update provides
the corresponding update for Ubuntu 22.10.
Original advisory details:
It was discovered that an integer overflow could be triggered in Libksba
when decoding certain data. An attacker could use this issue to cause a
denial of service (application crash) or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libksba vulnerability
vendor_ubuntu·2022-10-19
CVE-2022-3515 Libksba vulnerability
Title: Libksba vulnerability
Summary: Libksba could be made to crash or run programs if it decoded specially
crafted data.
It was discovered that an integer overflow could be triggered in Libksba
when decoding certain data. An attacker could use this issue to cause a
denial of service (application crash) or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libksba: integer overflow may lead to remote code execution
vendor_redhat·2022-10-17·CVSS 9.8
CVE-2022-3515 [CRITICAL] CWE-190 libksba: integer overflow may lead to remote code execution
libksba: integer overflow may lead to remote code execution
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
Package: libksba (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2022-3515: libksba - A vulnerability was found in the Libksba library due to an integer overflow with...
vendor_debian·2022·CVSS 9.8
CVE-2022-3515 [CRITICAL] CVE-2022-3515: libksba - A vulnerability was found in the Libksba library due to an integer overflow with...
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
Scope: local
bookworm: resolved (fixed in 1.6.2-1)
bullseye: resolved (fixed in 1.5.0-3+deb11u1)
forky: resolved (fixed in 1.6.2-1)
sid: resolved (fixed in 1.6.2-1)
trixie: resolved (fixed in 1.6.2-1)
OSV
CVE-2022-3515: A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser
osv·2023-01-12·CVSS 9.8
CVE-2022-3515 [CRITICAL] CVE-2022-3515: A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
GHSA
GHSA-58wq-p76f-6qjh: A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser
ghsa_unreviewed·2023-01-12
CVE-2022-3515 [CRITICAL] CWE-190 GHSA-58wq-p76f-6qjh: A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-3515https://bugzilla.redhat.com/show_bug.cgi?id=2135610https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582bhttps://security.netapp.com/advisory/ntap-20230706-0008/https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.htmlhttps://access.redhat.com/security/cve/CVE-2022-3515https://bugzilla.redhat.com/show_bug.cgi?id=2135610https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582bhttps://security.netapp.com/advisory/ntap-20230706-0008/https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html
2023-01-12
Published