CVE-2022-47629
published 2022-12-20CVE-2022-47629: Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.55%
72.3th percentile
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libksba | < libksba 1.6.3-1 (bookworm) | libksba 1.6.3-1 (bookworm) |
| gnupg | libksba | < 1.6.3 | 1.6.3 |
| gnupg | libksba | >= 0 < 1.5.0-3+deb11u2 | 1.5.0-3+deb11u2 |
| gnupg | libksba | >= 0 < 1.6.3-1 | 1.6.3-1 |
| gnupg | libksba | >= 0 < 1.6.3-1 | 1.6.3-1 |
| gnupg | libksba | >= 0 < 1.6.3-1 | 1.6.3-1 |
| msrc | cbl2_libksba_1.6.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_libksba_1.3.5-4_on_cbl_mariner_1.0 | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (libksba) — CVE-2022-47629
vendor_oracle·2023-04-15·CVSS 9.8
CVE-2022-47629 [CRITICAL] Oracle Oracle Communications Risk Matrix: Configuration (libksba) — CVE-2022-47629
Oracle Oracle Communications Risk Matrix: Configuration (libksba) vulnerability
CVE: CVE-2022-47629
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Ubuntu
Libksba vulnerability
vendor_ubuntu·2023-01-09
CVE-2022-47629 Libksba vulnerability
Title: Libksba vulnerability
Summary: Libksba could be made to crash or run programs if it processed specially
crafted data.
USN-5787-1 fixed vulnerabilities in Libksba. This update provides the
corresponding updates for Ubuntu 16.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Libksba incorrectly handled parsing CRL signatures.
A remote attacker could use this issue to cause Libksba to crash, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libksba vulnerability
vendor_ubuntu·2023-01-05
CVE-2022-47629 Libksba vulnerability
Title: Libksba vulnerability
Summary: Libksba could be made to crash or run programs if it processed specially
crafted data.
It was discovered that Libksba incorrectly handled parsing CRL signatures.
A remote attacker could use this issue to cause Libksba to crash, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
vendor_msrc·2022-12-13·CVSS 9.8
CVE-2022-47629 [CRITICAL] CWE-190 Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Ma
Red Hat
libksba: integer overflow to code execution
vendor_redhat·2022-10-17·CVSS 9.8
CVE-2022-47629 [CRITICAL] CWE-190 libksba: integer overflow to code execution
libksba: integer overflow to code execution
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
A vulnerability was found in the Libksba library, due to an integer overflow within the CRL's signature parser. This issue can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
Package: libksba (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2022-47629: libksba - Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL si...
vendor_debian·2022·CVSS 9.8
CVE-2022-47629 [CRITICAL] CVE-2022-47629: libksba - Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL si...
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Scope: local
bookworm: resolved (fixed in 1.6.3-1)
bullseye: resolved (fixed in 1.5.0-3+deb11u2)
forky: resolved (fixed in 1.6.3-1)
sid: resolved (fixed in 1.6.3-1)
trixie: resolved (fixed in 1.6.3-1)
GHSA
GHSA-j4m3-g4pc-cph8: Libksba before 1
ghsa_unreviewed·2022-12-21
CVE-2022-47629 [CRITICAL] CWE-190 GHSA-j4m3-g4pc-cph8: Libksba before 1
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
OSV
CVE-2022-47629: Libksba before 1
osv·2022-12-20·CVSS 9.8
CVE-2022-47629 [CRITICAL] CVE-2022-47629: Libksba before 1
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://dev.gnupg.org/T6284https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libksba.git%3Ba=commit%3Bh=f61a5ea4e0f6a80fd4b28ef0174bee77793cf070https://lists.debian.org/debian-lts-announce/2022/12/msg00035.htmlhttps://security.gentoo.org/glsa/202212-07https://security.netapp.com/advisory/ntap-20230316-0011/https://www.debian.org/security/2022/dsa-5305https://dev.gnupg.org/T6284https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libksba.git%3Ba=commit%3Bh=f61a5ea4e0f6a80fd4b28ef0174bee77793cf070https://lists.debian.org/debian-lts-announce/2022/12/msg00035.htmlhttps://security.gentoo.org/glsa/202212-07https://security.netapp.com/advisory/ntap-20230316-0011/https://www.debian.org/security/2022/dsa-5305
2022-12-20
Published