Debian Libksba vulnerabilities
10 known vulnerabilities affecting debian/libksba.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2LOW6
Vulnerabilities
Page 1 of 1
CVE-2022-3515CRITICALCVSS 9.8fixed in libksba 1.6.2-1 (bookworm)2022
CVE-2022-3515 [CRITICAL] CVE-2022-3515: libksba - A vulnerability was found in the Libksba library due to an integer overflow with...
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
Scope: local
bookworm: resolved (fixed in 1.6.2-1)
bullseye: resolved (fixed in 1.5.0
debian
CVE-2022-47629CRITICALCVSS 9.8fixed in libksba 1.6.3-1 (bookworm)2022
CVE-2022-47629 [CRITICAL] CVE-2022-47629: libksba - Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL si...
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Scope: local
bookworm: resolved (fixed in 1.6.3-1)
bullseye: resolved (fixed in 1.5.0-3+deb11u2)
forky: resolved (fixed in 1.6.3-1)
sid: resolved (fixed in 1.6.3-1)
trixie: resolved (fixed in 1.6.3-1)
debian
CVE-2016-4574HIGHCVSS 7.5fixed in libksba 1.3.4-3 (bookworm)2016
CVE-2016-4574 [HIGH] CVE-2016-4574: libksba - Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in L...
Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-4356.
Scope: local
bookworm: resolved (fixed in 1.3.4-3)
bullseye: resolved (fixed in 1.3.
debian
CVE-2016-4579HIGHCVSS 7.5fixed in libksba 1.3.4-3 (bookworm)2016
CVE-2016-4579 [HIGH] CVE-2016-4579: libksba - Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-o...
Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."
Scope: local
bookworm: resolved (fixed in 1.3.4-3)
bullseye: resolved (fixed in 1.3.4-3)
forky: resolved (fixed in 1.3.4-3)
sid: resolved (fixed in 1.3.4-3)
trixie: res
debian
CVE-2016-4353LOWCVSS 7.5fixed in libksba 1.3.3-1 (bookworm)2016
CVE-2016-4353 [HIGH] CVE-2016-4353: libksba - ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack ove...
ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.
Scope: local
bookworm: resolved (fixed in 1.3.3-1)
bullseye: resolved (fixed in 1.3.3-1)
forky: resolved (fixed in 1.3.3-1)
sid: resolved (fixed in 1.3.3-1)
trixie: resolved (fixed in 1.3.3-1)
debian
CVE-2016-4356LOWCVSS 7.5fixed in libksba 1.3.3-1 (bookworm)2016
CVE-2016-4356 [HIGH] CVE-2016-4356: libksba - The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 ...
The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.
Scope: local
bookworm: resolved (fixed in 1.3.3-1)
bullseye: resolved (fixed in 1.3.3-1)
forky: resolved (fixed in 1.3.3-1)
sid: resolved (fixed
debian
CVE-2016-4355LOWCVSS 7.5fixed in libksba 1.3.3-1 (bookworm)2016
CVE-2016-4355 [HIGH] CVE-2016-4355: libksba - Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote...
Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.3.3-1)
bullseye: resolved (fixed in 1.3.3-1)
forky: resolved (fixed in 1.3.3-1)
sid: resolved (fixed in 1.3.3-1)
trixie: resolved (fixed in 1.
debian
CVE-2016-4354LOWCVSS 7.5fixed in libksba 1.3.3-1 (bookworm)2016
CVE-2016-4354 [HIGH] CVE-2016-4354: libksba - ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which...
ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.3.3-1)
bullseye: resolved (fixed in 1.3.3-1)
forky: resolved (fixed in 1.3.3-1)
sid: resolved (fixed in 1.3.3-1)
trixie: resolve
debian
CVE-2014-9087LOWCVSS 7.5fixed in libksba 1.3.2-1 (bookworm)2014
CVE-2014-9087 [HIGH] CVE-2014-9087: gnupg2 - Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as us...
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2006-5111LOWCVSS 5.0fixed in libksba 0.9.14-1 (bookworm)2006
CVE-2006-5111 [MEDIUM] CVE-2006-5111: libksba - The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the ...
The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the newpg package on SUSE LINUX, allows attackers to cause a denial of service (application crash) via a malformed X.509 certificate in a signature.
Scope: local
bookworm: resolved (fixed in 0.9.14-1)
bullseye: resolved (fixed in 0.9.14-1)
forky: resolved (fixed in 0.9.14-1)
sid: resolved (f
debian